Skip to main content

Critical Privilege Escalation Vulnerability in Zoom Clients for Windows (CVE-2025-49457)

BACKGROUND

CVSS Score Base 9.6 Critical

An untrusted search path vulnerability has been found in Zoom Clients for Windows operating
system, allowing an unauthenticated attacker to escalate privileges via network access. This can
be achieved by placing a malicious DLL in a location that the Zoom client search without
specifying absolute paths. This vulnerability can lead to privilege escalation, arbitrary code
execution, and compromise of system integrity and availability.

IMPACT

  • Unauthorized attackers can gain elevated privileges on a target Windows system through
    network exploitation.
  • Attackers may potentially execute arbitrary code.
  • Sensitive systems may be exposed and compromised without proper authentication.

AFFECTED PRODUCTS

 Product Affected Versions
1Zoom WorkplaceEarlier than 6.3.10
2Zoom Workplace VDIEarlier than 6.3.10 (except 6.1.16 & 6.2.12)
3Zoom RoomsEarlier than 6.3.10
4Zoom Rooms ControllerEarlier than 6.3.10
5Zoom Meeting SDKEarlier than 6.3.10


RECOMMENDATIONS

  • Immediately update Zoom Clients for Windows to the latest version (6.3.0 or later) that
    contains the patch for this vulnerability. Latest updates can be downloaded at
    https://zoom.us/download
  • Enable automatic updates for the Zoom client software to ensure timely patching in the
    future.
  • Monitor network access and investigate any signs of unauthorized privilege escalation
    attempts.
  • Review and implement network access controls to limit exposure of Zoom client
    installations.
  • Enforce least-privilege access controls to limit the potential impact if a system is
    compromised.
  • Install antivirus software and keep it up to date.

REFERENCES


https://www.zoom.com/en/trust/security-bulletin/zsb-25030/

https://zeropath.com/blog/cve-2025-49457-zoom-untrusted-search-path-summary

https://securityonline.info/zoom-patches-critical-flaw-cve-2025-49457-windows-usersface-
privilege-escalation-risk/

 

About

Brunei Computer Emergency Response Team (BruCERT) was established in 2004 as the national and government CERT to deal with computer-related and internet-related security incidents in Negara Brunei Darussalam.