CVE-2025-0145

Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:video_software_development_kit:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:windows:*:*

History

20 Aug 2025, 12:38

Type Values Removed Values Added
CPE cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:video_software_development_kit:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:windows:*:*
Summary
  • (es) La ruta de búsqueda no confiable en el instalador de algunas aplicaciones de Zoom Workplace para Windows puede permitir que un usuario autorizado realice una escalada de privilegios a través del acceso local.
First Time Zoom meeting Software Development Kit
Zoom rooms Controller
Zoom rooms
Zoom workplace Desktop
Zoom video Software Development Kit
Zoom workplace Virtual Desktop Infrastructure
Zoom
References () https://www.zoom.com/en/trust/security-bulletin/zsb-25004/ - () https://www.zoom.com/en/trust/security-bulletin/zsb-25004/ - Vendor Advisory

30 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 20:15

Updated : 2025-08-20 12:38


NVD link : CVE-2025-0145

Mitre link : CVE-2025-0145

CVE.ORG link : CVE-2025-0145


JSON object : View

Products Affected

zoom

  • workplace_virtual_desktop_infrastructure
  • workplace_desktop
  • video_software_development_kit
  • meeting_software_development_kit
  • rooms
  • rooms_controller
CWE
CWE-426

Untrusted Search Path