Zoom
Zoom Rooms Controller: vulnerabilidades y CVE
Zoom Rooms Controller tiene 44 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE44
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-64739 | Alta (7.5) | 0.32% | — | 13 nov 2025 | External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2025-62483 | Alta (7.5) | 0.27% | — | 13 nov 2025 | Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2025-58135 | Media (6.5) | 0.26% | — | 9 sept 2025 | Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2025-58134 | Media (4.3) | 0.20% | — | 9 sept 2025 | Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access. |
| CVE-2025-49461 | Alta (7.4) | 0.31% | — | 9 sept 2025 | Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. |
| CVE-2025-49460 | Alta (7.5) | 0.27% | — | 9 sept 2025 | Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. |
| CVE-2025-49458 | Media (6.5) | 0.32% | — | 9 sept 2025 | Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-49457 | Alta (8.8) | 0.62% | — | 12 ago 2025 | Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access |
| CVE-2025-49456 | Media (5.1) | 0.11% | — | 12 ago 2025 | Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access. |
| CVE-2025-46786 | Media (6.1) | 0.29% | — | 14 may 2025 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access. |
| CVE-2025-46785 | Media (6.5) | 0.58% | — | 14 may 2025 | Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30668 | Media (6.5) | 0.55% | — | 14 may 2025 | Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30667 | Media (6.5) | 0.55% | — | 14 may 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30666 | Media (6.5) | 0.55% | — | 14 may 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30665 | Media (6.5) | 0.55% | — | 14 may 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30664 | Alta (8.2) | 0.27% | — | 14 may 2025 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. |
| CVE-2025-30663 | Alta (7) | 0.15% | — | 14 may 2025 | Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. |
| CVE-2025-30671 | Media (6.5) | 0.40% | — | 8 abr 2025 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30670 | Media (6.5) | 0.42% | — | 8 abr 2025 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-27443 | Media (5.5) | 0.16% | — | 8 abr 2025 | Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access. |
| CVE-2025-27442 | Media (5.2) | 0.24% | — | 8 abr 2025 | Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access. |
| CVE-2025-27441 | Media (5.2) | 0.26% | — | 8 abr 2025 | Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access. |
| CVE-2025-27440 | Alta (8.8) | 0.44% | — | 11 mar 2025 | Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. |
| CVE-2025-27439 | Alta (8.8) | 0.43% | — | 11 mar 2025 | Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. |
| CVE-2025-0151 | Alta (8.8) | 0.43% | — | 11 mar 2025 | Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. |
| CVE-2025-0149 | Alta (7.5) | 0.24% | — | 11 mar 2025 | Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access. |
| CVE-2024-45426 | Media (6.5) | 0.32% | — | 25 feb 2025 | Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access. |
| CVE-2024-45425 | Media (6.5) | 0.32% | — | 25 feb 2025 | Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access. |
| CVE-2024-45424 | Alta (7.5) | 0.37% | — | 25 feb 2025 | Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2024-45421 | Alta (8.8) | 0.61% | — | 25 feb 2025 | Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access. |
Otros productos de Zoom
Rooms · 109Meeting Software Development KIT · 84Workplace Desktop · 75Zoom · 64Workplace Virtual Desktop Infrastructure · 60Workplace · 43Meetings · 37Virtual Desktop Infrastructure · 25Video Software Development KIT · 23VDI Windows Meeting Clients · 9Zoom On-premise Meeting Connector MMR · 9Meeting Connector · 6