Advisory
14 August 2025
Background
CVSSv3 Score: Base 9.6 Critical
An untrusted search path vulnerability has been found in Zoom Clients for Windows operating system, allowing an unauthenticated attacker to escalate privileges via network access. This can be achieved by placing a malicious DLL in a location that the Zoom client search without specifying absolute paths. This vulnerability can lead to privilege escalation, arbitrary code execution, and compromise of system integrity and availability.
Impact
- Unauthorized attackers can gain elevated privileges on a target Windows system through network exploitation.
- Attackers may potentially execute arbitrary code.
- Sensitive systems may be exposed and compromised without proper authentication.
Affected Products
| Product | Affected Versions |
|---|---|
| Zoom Workplace | Earlier than 6.3.10 |
| Zoom Workplace VDI | Earlier than 6.3.10 (except 6.1.16 & 6.2.12) |
| Zoom Rooms | Earlier than 6.3.10 |
| Zoom Rooms Controller | Earlier than 6.3.10 |
| Zoom Meeting SDK | Earlier than 6.3.10 |
| DSM 7.2 | Upgrade to 7.2-64570-4 or above |
Recommendations
- Immediately update Zoom Clients for Windows to the latest version (6.3.0 or later) that contains the patch for this vulnerability. Latest updates can be downloaded at https://zoom.us/download
- Enable automatic updates for the Zoom client software to ensure timely patching in the future.
- Monitor network access and investigate any signs of unauthorized privilege escalation attempts.
- Review and implement network access controls to limit exposure of Zoom client installations.
- Enforce least-privilege access controls to limit the potential impact if a system is compromised.
- Install antivirus software and keep it up to date.
References