CRITICAL🇵🇱 Wersja polska

CVE-2025-49457

CVSS 9.6v3.1pub. 2025-08-12upd. 2025-09-08

Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

🤖 AI Analysis
How it works

The error consists in the application searching for DLL libraries or other executable resources in untrusted paths, which enables substitution of a malicious executable file. An attacker with network access can trick a user into performing an action (UI: Required), which will cause the application to load a malicious file from a compromised or controlled path. Due to scope change (Scope: Changed), the effects may extend beyond the Zoom process itself and impact the broader system context.

Impact

A successful attack may allow the attacker to obtain elevated privileges in the Windows operating system, as well as compromise confidentiality, integrity and availability of data — all three CIA components were assessed as HIGH.

Mitigation & patch

Security patches available from the vendor should be applied in accordance with references published in the Zoom security bulletin at https://www.zoom.com/en/trust/security-bulletin/zsb-25030. Immediate update of all mentioned Zoom components in Windows environments is recommended.

Who is affected

Zoom Meeting Software Development Kit (Windows), Zoom Rooms (Windows), Zoom Workplace Desktop (Windows), Zoom Workplace Virtual Desktop Infrastructure (Windows), Zoom Rooms Controller (Windows) — specific versions indicated in vendor references (zsb-25030).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Zoom Meeting Software Development Kit

    APP
    Zoom
    < 6.3.10
  • Zoom Rooms

    APP
    Zoom
    < 6.3.10
  • Zoom Rooms Controller

    APP
    Zoom
    < 6.3.10
  • Zoom Workplace Desktop

    APP
    Zoom
    < 6.3.10
  • Zoom Workplace Virtual Desktop Infrastructure

    APP
    Zoom
    < 6.1.166.2.10 – 6.2.12 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-53412CRITICAL9.8PL ✓same product

Przejęcie konta przez sieć — błąd walidacji w Zoom Client dla Windows

CVE-2026-30903CRITICAL9.6PL ✓same product

Zoom Workplace dla Windows — privilege escalation przez kontrolę ścieżki pliku w funkcji Mail

CVE-2024-24691CRITICAL9.6PL ✓same product

Privilege escalation w Zoom Desktop Client, VDI Client i Meeting SDK dla Windows

CVE-2026-53409HIGH7.8PL ✓same product

Privilege escalation w Zoom Rooms dla Windows (przed wersją 7.1.0)

CVE-2026-53410HIGH7.0PL ✓same product

TOCTOU race condition w Zoom Client dla Windows — privilege escalation