← Back to CVE List
CVE-2025-49456NVD
Vulnerability Summary
Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access.
CVSS v3.1 Base Metrics — Score 6.2 (MEDIUM)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityHigh
AvailabilityNone
Affected & Patched Versions
- Zoom Meeting Software Development Kit < 6.4.10
- Zoom Rooms < 6.4.5
- Zoom Rooms Controller < 6.4.5
- Zoom Workplace Desktop < 6.4.10
- Zoom Workplace Virtual Desktop Infrastructure < 6.2.15
- Zoom Workplace Virtual Desktop Infrastructure >= 6.3.10 and < 6.3.12
- Zoom Meeting Software Development Kit 6.4.10
- Zoom Rooms 6.4.5
- Zoom Rooms Controller 6.4.5
- Zoom Workplace Desktop 6.4.10
- Zoom Workplace Virtual Desktop Infrastructure 6.2.15
- Zoom Workplace Virtual Desktop Infrastructure 6.3.12