Zoom
Zoom Rooms Controller: vulnerabilities and CVEs
Zoom Rooms Controller has 44 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs44
Last 12 months2
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64739 | High (7.5) | 0.32% | — | Nov 13, 2025 | External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2025-62483 | High (7.5) | 0.27% | — | Nov 13, 2025 | Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2025-58135 | Medium (6.5) | 0.26% | — | Sep 9, 2025 | Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2025-58134 | Medium (4.3) | 0.20% | — | Sep 9, 2025 | Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access. |
| CVE-2025-49461 | High (7.4) | 0.31% | — | Sep 9, 2025 | Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. |
| CVE-2025-49460 | High (7.5) | 0.27% | — | Sep 9, 2025 | Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. |
| CVE-2025-49458 | Medium (6.5) | 0.32% | — | Sep 9, 2025 | Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-49457 | High (8.8) | 0.62% | — | Aug 12, 2025 | Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access |
| CVE-2025-49456 | Medium (5.1) | 0.11% | — | Aug 12, 2025 | Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access. |
| CVE-2025-46786 | Medium (6.1) | 0.29% | — | May 14, 2025 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access. |
| CVE-2025-46785 | Medium (6.5) | 0.58% | — | May 14, 2025 | Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30668 | Medium (6.5) | 0.55% | — | May 14, 2025 | Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30667 | Medium (6.5) | 0.55% | — | May 14, 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30666 | Medium (6.5) | 0.55% | — | May 14, 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30665 | Medium (6.5) | 0.55% | — | May 14, 2025 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30664 | High (8.2) | 0.27% | — | May 14, 2025 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. |
| CVE-2025-30663 | High (7) | 0.15% | — | May 14, 2025 | Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. |
| CVE-2025-30671 | Medium (6.5) | 0.40% | — | Apr 8, 2025 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-30670 | Medium (6.5) | 0.42% | — | Apr 8, 2025 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-27443 | Medium (5.5) | 0.16% | — | Apr 8, 2025 | Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access. |
| CVE-2025-27442 | Medium (5.2) | 0.24% | — | Apr 8, 2025 | Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access. |
| CVE-2025-27441 | Medium (5.2) | 0.26% | — | Apr 8, 2025 | Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access. |
| CVE-2025-27440 | High (8.8) | 0.44% | — | Mar 11, 2025 | Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. |
| CVE-2025-27439 | High (8.8) | 0.43% | — | Mar 11, 2025 | Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. |
| CVE-2025-0151 | High (8.8) | 0.43% | — | Mar 11, 2025 | Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. |
| CVE-2025-0149 | High (7.5) | 0.24% | — | Mar 11, 2025 | Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access. |
| CVE-2024-45426 | Medium (6.5) | 0.32% | — | Feb 25, 2025 | Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access. |
| CVE-2024-45425 | Medium (6.5) | 0.32% | — | Feb 25, 2025 | Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access. |
| CVE-2024-45424 | High (7.5) | 0.37% | — | Feb 25, 2025 | Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2024-45421 | High (8.8) | 0.61% | — | Feb 25, 2025 | Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access. |
Other products by Zoom
Rooms · 109Meeting Software Development KIT · 84Workplace Desktop · 75Zoom · 64Workplace Virtual Desktop Infrastructure · 60Workplace · 43Meetings · 37Virtual Desktop Infrastructure · 25Video Software Development KIT · 23VDI Windows Meeting Clients · 9Zoom On-premise Meeting Connector MMR · 9Meeting Connector · 6