TROYANOSYVIRUS
Back to CVEs

CVE-2025-49457

CRITICAL
9.6

Description

Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

CVE Details

CVSS v3.1 Score9.6
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
Published8/12/2025
Last Modified9/8/2025
Sourcenvd
Honeypot Sightings0

Affected Products

zoom:meeting_software_development_kitzoom:roomszoom:rooms_controllerzoom:workplace_desktopzoom:workplace_virtual_desktop_infrastructure

Weaknesses (CWE)

CWE-426

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.