Zoom Workplace Apps for Windows
by Zoom Video Communications, Inc.
CVEs (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-27240 | Hig | 0.46 | 7.1 | 0.00 | Jul 15, 2024 | Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access. | ||
| CVE-2024-27244 | Med | 0.44 | 6.7 | 0.00 | May 15, 2024 | Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access. | ||
| CVE-2025-30666 | Med | 0.42 | 6.5 | 0.01 | May 14, 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | ||
| CVE-2025-30665 | Med | 0.42 | 6.5 | 0.01 | May 14, 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | ||
| CVE-2025-30671 | Med | 0.42 | 6.5 | 0.00 | Apr 8, 2025 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | ||
| CVE-2025-30670 | Med | 0.42 | 6.5 | 0.00 | Apr 8, 2025 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | ||
| CVE-2024-39827 | Med | 0.36 | 5.5 | 0.00 | Jul 15, 2024 | Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access. | ||
| CVE-2025-0145 | Med | 0.30 | 4.6 | 0.00 | Jan 30, 2025 | Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access. | ||
| CVE-2025-27443 | Low | 0.18 | 2.8 | 0.00 | Apr 8, 2025 | Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access. |
- risk 0.46cvss 7.1epss 0.00
Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.
- risk 0.44cvss 6.7epss 0.00
Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
- risk 0.42cvss 6.5epss 0.01
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
- risk 0.42cvss 6.5epss 0.01
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
- risk 0.42cvss 6.5epss 0.00
Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
- risk 0.42cvss 6.5epss 0.00
Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.
- risk 0.30cvss 4.6epss 0.00
Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.
- risk 0.18cvss 2.8epss 0.00
Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access.