Zoom Workplace Virtual Desktop Infrastructure
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Zoom Workplace Virtual Desktop Infrastructure.
By the Year
In 2025 there have been 9 vulnerabilities in Zoom Workplace Virtual Desktop Infrastructure with an average score of 7.4 out of ten. Last year, in 2024 Workplace Virtual Desktop Infrastructure had 12 security vulnerabilities published. Right now, Workplace Virtual Desktop Infrastructure is on track to have less security vulnerabilities in 2025 than it did last year. However, the average CVE base score of the vulnerabilities in 2025 is greater by 1.01.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2025 | 9 | 7.36 |
| 2024 | 12 | 6.35 |
It may take a day or so for new Workplace Virtual Desktop Infrastructure vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Zoom Workplace Virtual Desktop Infrastructure Security Vulnerabilities
Zoom Workplace App Windows Null Deref Allows Authenticated DoS
CVE-2025-30665
- May 14, 2025
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
Zoom Workplace Apps Windows: Authenticated DoS via NULL Pointer Deref
CVE-2025-30666
- May 14, 2025
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
Zoom Workplace Apps Windows NPE DoS via Network Access
CVE-2025-30670
- April 08, 2025
Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
CVE-2025-30671: Zoom Workplace Windows App DoS via NPE
CVE-2025-30671
- April 08, 2025
Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
Zoom Workplace App: Unprivileged DOS via Unverified Data
CVE-2025-0149
7.5 - High
- March 11, 2025
Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access.
Zoom Apps Buffer Overflow Escalation via Authenticated Network Access
CVE-2024-45421
8.8 - High
- February 25, 2025
Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.
Zoom Workplace Apps: Unauth Data Disclosure via Business Logic Flaw
CVE-2024-45424
7.5 - High
- February 25, 2025
Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access.
Zoom Workplace App Privilege Escalation: Info Disclosure via Network
CVE-2024-45425
6.5 - Medium
- February 25, 2025
Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
Zoom Workplace App Ownership Flaw Enables Info Disclosure
CVE-2024-45426
6.5 - Medium
- February 25, 2025
Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
Zoom Apps Information Disclosure Vulnerability
CVE-2024-45419
7.5 - High
- November 19, 2024
Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access.
Zoom Workplace SDK Authenticated info disclosure via network
CVE-2024-39818
6.5 - Medium
- August 14, 2024
Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access.
Insufficiently Protected Credentials
Zoom Workplace Apps/SDKs/Rooms Clients: Missing Auth Allows Info Disclosure
CVE-2024-39823
4.9 - Medium
- August 14, 2024
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
AuthZ
Zoom Workplace Apps/SDKs/Rooms: Missing Auth Enables Info Disclosure
CVE-2024-39824
4.9 - Medium
- August 14, 2024
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
AuthZ
Zoom Workplace Apps Client buffer overflow allows privileged escalation via net
CVE-2024-39825
8.5 - High
- August 14, 2024
Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.
Memory Corruption
Zoom Workplace Apps/SDKs Missing Auth Enabling Info Disclosure
CVE-2024-42434
4.9 - Medium
- August 14, 2024
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
AuthZ
Zoom Info Disclosure via Network (CVE-2024-42435)
CVE-2024-42435
4.9 - Medium
- August 14, 2024
Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
Zoom Workplace Buffer Overflow Allows Authenticated DoS
CVE-2024-42436
6.5 - Medium
- August 14, 2024
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
Memory Corruption
Zoom Workplace/Rooms Buffer Overflow: Authenticated DoS via Network
CVE-2024-42437
6.5 - Medium
- August 14, 2024
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
Memory Corruption
Zoom Workplace Apps/SDK Buffer Overflow Enables Authenticated DoS
CVE-2024-42438
6.5 - Medium
- August 14, 2024
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
Memory Corruption
Zoom Workplace App Race Condition: Authenticated Info Disclosure (CVE-202439826)
CVE-2024-39826
6.8 - Medium
- July 15, 2024
Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network access.
TOCTTOU
Zoom Apps Windows Installer PrivEsc via Input Validation
CVE-2024-27240
7.8 - High
- July 15, 2024
Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Zoom Workplace Virtual Desktop Infrastructure or by Zoom? Click the Watch button to subscribe.