Zoom
Zoom Rooms: vulnerabilidades y CVE
Zoom Rooms tiene 109 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE109
Últimos 12 meses11
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-53410 | Alta (7) | 0.10% | — | 16 jul 2026 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges. |
| CVE-2026-53409 | Alta (7.8) | 0.17% | — | 16 jul 2026 | Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access. |
| CVE-2026-30906 | Alta (7.8) | 0.16% | — | 13 may 2026 | Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access. |
| CVE-2026-30902 | Alta (7.8) | 0.14% | — | 11 mar 2026 | Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access. |
| CVE-2026-30901 | Alta (7.8) | 0.15% | — | 11 mar 2026 | Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduct an escalation of privilege via local access. |
| CVE-2025-67461 | Media (5.5) | 0.14% | — | 10 dic 2025 | External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of information via local access. |
| CVE-2025-67460 | Alta (7.8) | 0.16% | — | 10 dic 2025 | Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via local access. |
| CVE-2025-64739 | Alta (7.5) | 0.32% | — | 13 nov 2025 | External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2025-62483 | Alta (7.5) | 0.27% | — | 13 nov 2025 | Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2025-58133 | Alta (7.5) | 0.28% | — | 15 oct 2025 | Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2025-58132 | Media (6.5) | 1.8% | — | 15 oct 2025 | Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access. |
| CVE-2025-58135 | Media (6.5) | 0.26% | — | 9 sept 2025 | Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2025-58134 | Media (4.3) | 0.20% | — | 9 sept 2025 | Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access. |
| CVE-2025-49461 | Alta (7.4) | 0.31% | — | 9 sept 2025 | Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. |
| CVE-2025-49460 | Alta (7.5) | 0.27% | — | 9 sept 2025 | Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. |
| CVE-2025-49458 | Media (6.5) | 0.32% | — | 9 sept 2025 | Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-49457 | Alta (8.8) | 0.62% | — | 12 ago 2025 | Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access |
| CVE-2025-49456 | Media (5.1) | 0.11% | — | 12 ago 2025 | Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access. |
| CVE-2025-46786 | Media (6.1) | 0.29% | — | 14 may 2025 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access. |
| CVE-2025-46785 | Media (6.5) | 0.58% | — | 14 may 2025 | Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30668 | Media (6.5) | 0.55% | — | 14 may 2025 | Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30667 | Media (6.5) | 0.55% | — | 14 may 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30666 | Media (6.5) | 0.55% | — | 14 may 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30665 | Media (6.5) | 0.55% | — | 14 may 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30664 | Alta (8.2) | 0.27% | — | 14 may 2025 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. |
| CVE-2025-30663 | Alta (7) | 0.15% | — | 14 may 2025 | Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. |
| CVE-2025-30671 | Media (6.5) | 0.40% | — | 8 abr 2025 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30670 | Media (6.5) | 0.42% | — | 8 abr 2025 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-27443 | Media (5.5) | 0.16% | — | 8 abr 2025 | Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access. |
| CVE-2025-27442 | Media (5.2) | 0.24% | — | 8 abr 2025 | Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access. |
Otros productos de Zoom
Meeting Software Development KIT · 84Workplace Desktop · 75Zoom · 64Workplace Virtual Desktop Infrastructure · 60Rooms Controller · 44Workplace · 43Meetings · 37Virtual Desktop Infrastructure · 25Video Software Development KIT · 23VDI Windows Meeting Clients · 9Zoom On-premise Meeting Connector MMR · 9Meeting Connector · 6