Rooms
by Zoom Video Communications, Inc.
CVEs (109)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-58132 | Med | 0.27 | 4.1 | 0.02 | Oct 15, 2025 | Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access. | ||
| CVE-2023-34121 | Med | 0.27 | 4.1 | 0.01 | Jun 13, 2023 | Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access. | ||
| CVE-2025-0146 | Low | 0.25 | 3.9 | 0.00 | Jan 30, 2025 | Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via local access. | ||
| CVE-2023-39206 | Low | 0.24 | 3.7 | 0.01 | Nov 14, 2023 | Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. | ||
| CVE-2022-28766 | Low | 0.21 | 3.3 | 0.01 | Nov 17, 2022 | Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of… | ||
| CVE-2022-28764 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2022 | The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure… | ||
| CVE-2025-0144 | Low | 0.20 | 3.1 | 0.00 | Jan 30, 2025 | Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network access. | ||
| CVE-2023-39202 | Low | 0.20 | 3.1 | 0.00 | Nov 14, 2023 | Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access. | ||
| CVE-2025-27443 | Low | 0.18 | 2.8 | 0.00 | Apr 8, 2025 | Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access. |
- risk 0.27cvss 4.1epss 0.02
Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.
- risk 0.27cvss 4.1epss 0.01
Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access.
- risk 0.25cvss 3.9epss 0.00
Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via local access.
- risk 0.24cvss 3.7epss 0.01
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
- risk 0.21cvss 3.3epss 0.01
Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of…
- risk 0.21cvss 3.3epss 0.00
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure…
- risk 0.20cvss 3.1epss 0.00
Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network access.
- risk 0.20cvss 3.1epss 0.00
Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.
- risk 0.18cvss 2.8epss 0.00
Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access.
Page 6 of 6