CVE-2025-0145

Severity CVSS v4.0:
Pending analysis
Type:
CWE-426 Untrusted Search Path
Publication date:
30/01/2025
Last modified:
20/08/2025

Description

Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:windows:*:* 6.2.5 (excluding)
cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:* 6.2.5 (excluding)
cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:windows:*:* 6.2.5 (excluding)
cpe:2.3:a:zoom:video_software_development_kit:*:*:*:*:*:windows:*:* 6.2.5 (excluding)
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:windows:*:* 6.2.5 (excluding)
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:windows:*:* 6.0.15 (excluding)
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:windows:*:* 6.0.16 (including) 6.1.13 (excluding)


References to Advisories, Solutions, and Tools