← Back to CVE List
CVE-2025-49457NVD
Vulnerability Summary
Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access
CVSS v3.1 Base Metrics — Score 9.6 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Zoom Meeting Software Development Kit < 6.3.10
- Zoom Rooms < 6.3.10
- Zoom Rooms Controller < 6.3.10
- Zoom Workplace Desktop < 6.3.10
- Zoom Workplace Virtual Desktop Infrastructure < 6.1.16
- Zoom Workplace Virtual Desktop Infrastructure >= 6.2.10 and < 6.2.12
- Zoom Meeting Software Development Kit 6.3.10
- Zoom Rooms 6.3.10
- Zoom Rooms Controller 6.3.10
- Zoom Workplace Desktop 6.3.10
- Zoom Workplace Virtual Desktop Infrastructure 6.1.16
- Zoom Workplace Virtual Desktop Infrastructure 6.2.12