Workplace Virtual Desktop Infrastructure Zoom Workplace Virtual Desktop Infrastructure

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Zoom Workplace Virtual Desktop Infrastructure.

By the Year

In 2025 there have been 9 vulnerabilities in Zoom Workplace Virtual Desktop Infrastructure with an average score of 7.4 out of ten. Last year, in 2024 Workplace Virtual Desktop Infrastructure had 12 security vulnerabilities published. Right now, Workplace Virtual Desktop Infrastructure is on track to have less security vulnerabilities in 2025 than it did last year. However, the average CVE base score of the vulnerabilities in 2025 is greater by 1.01.

Year Vulnerabilities Average Score
2025 9 7.36
2024 12 6.35

It may take a day or so for new Workplace Virtual Desktop Infrastructure vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Zoom Workplace Virtual Desktop Infrastructure Security Vulnerabilities

Zoom Workplace App Windows Null Deref Allows Authenticated DoS
CVE-2025-30665 - May 14, 2025

NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Zoom Workplace Apps Windows: Authenticated DoS via NULL Pointer Deref
CVE-2025-30666 - May 14, 2025

NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Zoom Workplace Apps Windows NPE DoS via Network Access
CVE-2025-30670 - April 08, 2025

Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

CVE-2025-30671: Zoom Workplace Windows App DoS via NPE
CVE-2025-30671 - April 08, 2025

Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Zoom Workplace App: Unprivileged DOS via Unverified Data
CVE-2025-0149 7.5 - High - March 11, 2025

Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access.

Zoom Apps Buffer Overflow Escalation via Authenticated Network Access
CVE-2024-45421 8.8 - High - February 25, 2025

Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.

Zoom Workplace Apps: Unauth Data Disclosure via Business Logic Flaw
CVE-2024-45424 7.5 - High - February 25, 2025

Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access.

Zoom Workplace App Privilege Escalation: Info Disclosure via Network
CVE-2024-45425 6.5 - Medium - February 25, 2025

Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.

Zoom Workplace App Ownership Flaw Enables Info Disclosure
CVE-2024-45426 6.5 - Medium - February 25, 2025

Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.

Zoom Apps Information Disclosure Vulnerability
CVE-2024-45419 7.5 - High - November 19, 2024

Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access.

Zoom Workplace SDK Authenticated info disclosure via network
CVE-2024-39818 6.5 - Medium - August 14, 2024

Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access.

Insufficiently Protected Credentials

Zoom Workplace Apps/SDKs/Rooms Clients: Missing Auth Allows Info Disclosure
CVE-2024-39823 4.9 - Medium - August 14, 2024

Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

AuthZ

Zoom Workplace Apps/SDKs/Rooms: Missing Auth Enables Info Disclosure
CVE-2024-39824 4.9 - Medium - August 14, 2024

Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

AuthZ

Zoom Workplace Apps Client buffer overflow allows privileged escalation via net
CVE-2024-39825 8.5 - High - August 14, 2024

Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.

Memory Corruption

Zoom Workplace Apps/SDKs Missing Auth Enabling Info Disclosure
CVE-2024-42434 4.9 - Medium - August 14, 2024

Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

AuthZ

Zoom Info Disclosure via Network (CVE-2024-42435)
CVE-2024-42435 4.9 - Medium - August 14, 2024

Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

Zoom Workplace Buffer Overflow Allows Authenticated DoS
CVE-2024-42436 6.5 - Medium - August 14, 2024

Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

Memory Corruption

Zoom Workplace/Rooms Buffer Overflow: Authenticated DoS via Network
CVE-2024-42437 6.5 - Medium - August 14, 2024

Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

Memory Corruption

Zoom Workplace Apps/SDK Buffer Overflow Enables Authenticated DoS
CVE-2024-42438 6.5 - Medium - August 14, 2024

Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

Memory Corruption

Zoom Workplace App Race Condition: Authenticated Info Disclosure (CVE-202439826)
CVE-2024-39826 6.8 - Medium - July 15, 2024

Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network access.

TOCTTOU

Zoom Apps Windows Installer PrivEsc via Input Validation
CVE-2024-27240 7.8 - High - July 15, 2024

Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Zoom Workplace Virtual Desktop Infrastructure or by Zoom? Click the Watch button to subscribe.

Zoom
Vendor

subscribe