Zoom Zoom

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Zoom product.

RSS Feeds for Zoom security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Zoom products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Zoom Sorted by Most Security Vulnerabilities since 2018

Zoom86 vulnerabilities

Zoom Rooms77 vulnerabilities

Zoom Workplace Desktop39 vulnerabilities

Zoom Rooms Controller22 vulnerabilities

Zoom Workplace21 vulnerabilities

Zoom Macos Meeting Sdk4 vulnerabilities

Zoom Meeting Sdk3 vulnerabilities

By the Year

In 2026 there have been 0 vulnerabilities in Zoom. Last year, in 2025 Zoom had 41 security vulnerabilities published. Right now, Zoom is on track to have less security vulnerabilities in 2026 than it did last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 41 6.24
2024 36 6.45
2023 62 7.21
2022 28 7.34
2021 19 7.64
2020 8 7.54
2019 3 7.27
2018 1 9.80

It may take a day or so for new Zoom vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Zoom Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2025-67460 Dec 10, 2025
EoP via Software Downgrade in Zoom Rooms <6.6.0 on Windows Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via local access.
Rooms
CVE-2025-67461 Dec 10, 2025
Zoom Rooms for macOS <6.6.0: External File Name Control Local Info Disclosure External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of information via local access.
Rooms
CVE-2025-62484 Nov 13, 2025
Zoom Workplace Client <=6.5.9 Inefficient RE Allows Escalation via Network Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
Workplace
CVE-2025-62483 Nov 13, 2025
Zoom Client <6.5.10: Info Leak via Improper Sensitive Data Erasure Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.
Zoom
CVE-2025-62482 Nov 13, 2025
Zoom Workplace XSS (v <6.5.10) for Windows Allows Remote Integrity Impact Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.
Workplace
CVE-2025-30662 Nov 13, 2025
Zoom Workplace VDI Plugin macOS Installer Symlink Follow (<=v6.5.10) Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.
Zoom
CVE-2025-30669 Nov 13, 2025
Zoom Client Cert Validation Flaw Enables Info Disclosure via Adjacent Access Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.
Zoom
CVE-2025-64741 Nov 13, 2025
Zoom Workplace Android <=6.5.9 Improper Auth Escalation via Network Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
Zoom
CVE-2025-64740 Nov 13, 2025
Zoom Workplace VDI Client: Installer Crypto Signature Issue (CVE-2025-64740) Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
Zoom
CVE-2025-64739 Nov 13, 2025
Zoom Client Path Injection Enables Unauth Data Disclosure via Network External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.
Zoom
CVE-2025-64738 Nov 13, 2025
Zoom Workplace <6.5.10: External file name/path control leads to info disclosure External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of information via local access.
Zoom
CVE-2025-58133 Oct 15, 2025
Zoom Rooms Client Auth Bypass <6.5.1: Info Disclosure via Network Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a disclosure of information via network access.
Zoom
Rooms
CVE-2025-58132 Oct 15, 2025
Zoom Windows Client Auth Command Injection via Network Access Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.
Zoom
CVE-2025-58134 Sep 09, 2025
Zoom Workplace Client auth flaw allows integrity impact via network Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access.
Zoom
CVE-2025-49461 Sep 09, 2025
XSS in Zoom Workplace Clients leading to DoS via Network Access Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.
Zoom
CVE-2025-49460 Sep 09, 2025
Uncontrolled Resource Consumption Leads to DoS in Zoom Workplace Client Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.
CVE-2025-49459 Sep 09, 2025
Zoom Workplace Windows ARM Installer Missing Auth EoP before 6.5.0 Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6.5.0 may allow an authenticated user to conduct an escalation of privilege via local access.
CVE-2025-49462 Jul 10, 2025
XSS in Zoom Client before v6.4.5 discloses info via network access Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.
Zoom
CVE-2025-49463 Jul 10, 2025
Zoom iOS Client <6.4.5: Control Flow Flaw Exposes Info Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated user to conduct a disclosure of information via network access.
Zoom
CVE-2025-49464 Jul 10, 2025
Buffer Overflow in Zoom Client for Windows Enables DoS via Network Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.
Zoom
CVE-2025-46788 Jul 10, 2025
Zoom Workplace Improper Cert Validation (v<6.4.13) May Reveal Network Info Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via network access.
Workplace Desktop
CVE-2025-30668 May 14, 2025
Zoom Workplace Integer Underflow Lets Auth User DoS via Network Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.
Zoom
CVE-2025-46786 May 14, 2025
Zoom Workplace App: Authenticated User Can Compromise App Integrity via Network Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access.
Zoom
CVE-2025-30664 May 14, 2025
Zoom Workplace Apps Priv Escal via Improper Special Element Neutralization Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.
Zoom
CVE-2025-30665 May 14, 2025
Zoom Workplace App Windows Null Deref Allows Authenticated DoS NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
Meeting Software Development Kit
Rooms
Rooms Controller
And others...
CVE-2025-30666 May 14, 2025
Zoom Workplace Apps Windows: Authenticated DoS via NULL Pointer Deref NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
Meeting Software Development Kit
Rooms
Rooms Controller
And others...
CVE-2025-30671 Apr 08, 2025
CVE-2025-30671: Zoom Workplace Windows App DoS via NPE Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
Rooms
Rooms Controller
Workplace Desktop
And others...
CVE-2025-27443 Apr 08, 2025
Insecure Default Variable Init in Zoom Workplace Apps (Win) Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access.
Rooms
Rooms Controller
Workplace Desktop
And others...
CVE-2025-30670 Apr 08, 2025
Zoom Workplace Apps Windows NPE DoS via Network Access Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
Rooms
Rooms Controller
Workplace Desktop
And others...
CVE-2025-0150 Mar 11, 2025
Zoom Workplace Apps iOS <6.3.0 Authenticated User DDoS via Network Incorrect behavior order in some Zoom Workplace Apps for iOS before version 6.3.0 may allow an authenticated user to conduct a denial of service via network access.
Meeting Software Development Kit
Workplace
CVE-2025-0149 Mar 11, 2025
Zoom Workplace App: Unprivileged DOS via Unverified Data Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access.
Meeting Software Development Kit
Workplace
Workplace Desktop
And others...
CVE-2024-27239 Feb 25, 2025
Zoom Workplace Apps UAF Authenticated DoS Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.
Zoom
CVE-2024-45426 Feb 25, 2025
Zoom Workplace App Ownership Flaw Enables Info Disclosure Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
Rooms Controller
Rooms
Meeting Software Development Kit
And others...
CVE-2024-45418 Feb 25, 2025
Zoom macOS App Pre-6.1.5 Symlink Following in Installer Causing Priv Escalation Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.
Workplace Desktop
Meeting Software Development Kit
Rooms
And others...
CVE-2024-45417 Feb 25, 2025
Uncontrolled Res Consumption in Zoom App Installer (<6.1.5) on macOS Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privileged user to conduct a disclosure of information via local access.
Workplace Desktop
Meeting Software Development Kit
Rooms
And others...
CVE-2024-45425 Feb 25, 2025
Zoom Workplace App Privilege Escalation: Info Disclosure via Network Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
Rooms Controller
Rooms
Meeting Software Development Kit
And others...
CVE-2024-45424 Feb 25, 2025
Zoom Workplace Apps: Unauth Data Disclosure via Business Logic Flaw Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access.
Rooms Controller
Rooms
Meeting Software Development Kit
And others...
CVE-2024-45421 Feb 25, 2025
Zoom Apps Buffer Overflow Escalation via Authenticated Network Access Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.
Meeting Software Development Kit
Rooms
Workplace
And others...
CVE-2025-0143 Jan 30, 2025
OOB Write in Zoom Workplace App <=6.2.5 (Linux) - DoS Out-of-bounds write in the Zoom Workplace App for Linux before version 6.2.5 may allow an unauthorized user to conduct a denial of service via network access.
Meeting Software Development Kit
Video Software Development Kit
Workplace Desktop
And others...
CVE-2025-0146 Jan 30, 2025
Zoom Workplace App macOS <6.2.10 Symlink Following in Installer Local DOS Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via local access.
Rooms
Rooms Controller
Workplace Desktop
And others...
CVE-2025-0147 Jan 30, 2025
Zoom Workplace App (Linux) v<6.2.10 - EoP via Net Type Confusion Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation of privilege via network access.
Meeting Software Development Kit
Video Software Development Kit
Workplace Desktop
And others...
CVE-2024-45419 Nov 19, 2024
Zoom Apps Information Disclosure Vulnerability Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access.
Zoom
Meeting Software Development Kit
Rooms
And others...
CVE-2024-45422 Nov 19, 2024
Zoom Apps: Improper Input Validation Leading to Denial of Service Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access.
Zoom
Meeting Software Development Kit
Rooms
And others...
CVE-2024-45420 Nov 19, 2024
Zoom Apps Uncontrolled Resource Consumption Denial of Service Vulnerability Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a denial of service via network access.
Zoom
Meeting Software Development Kit
Rooms
And others...
CVE-2024-42434 Aug 14, 2024
Zoom Workplace Apps/SDKs Missing Auth Enabling Info Disclosure Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
Rooms Controller
Rooms
Meeting Software Development Kit
And others...
CVE-2024-39825 Aug 14, 2024
Zoom Workplace Apps Client buffer overflow allows privileged escalation via net Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.
Workplace
Workplace Desktop
Workplace Virtual Desktop Infrastructure
And others...
CVE-2024-42435 Aug 14, 2024
Zoom Info Disclosure via Network (CVE-2024-42435) Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
Rooms Controller
Rooms
Meeting Software Development Kit
And others...
CVE-2024-42438 Aug 14, 2024
Zoom Workplace Apps/SDK Buffer Overflow Enables Authenticated DoS Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
Rooms Controller
Rooms
Meeting Software Development Kit
And others...
CVE-2024-42437 Aug 14, 2024
Zoom Workplace/Rooms Buffer Overflow: Authenticated DoS via Network Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
Rooms Controller
Rooms
Meeting Software Development Kit
And others...
CVE-2024-42436 Aug 14, 2024
Zoom Workplace Buffer Overflow Allows Authenticated DoS Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
Rooms Controller
Rooms
Meeting Software Development Kit
And others...
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.