Home/Product/zoom workplace
Product

zoom workplace

39 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-62484
< 6.5.10
Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated use
8.1HIGH
CVE-2025-64741
< 6.5.10
Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct a
8.1HIGH
CVE-2025-49461
< 6.5.0
Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via networ
4.3MEDIUM
CVE-2025-49460
< 6.5.0
Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of servi
4.3MEDIUM
CVE-2025-46786
< 6.4.0
Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access.
4.3MEDIUM
CVE-2025-30668
< 6.4.0
Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.
6.5MEDIUM
CVE-2025-30667
< 6.4.0
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service vi
6.5MEDIUM
CVE-2025-30664
< 6.4.0
Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local a
6.6MEDIUM
CVE-2025-30663
< 6.4.0
Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of p
8.8HIGH
CVE-2025-27442
< 6.3.10
Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent net
4.6MEDIUM
CVE-2025-27441
< 6.3.10
Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent net
4.6MEDIUM
CVE-2025-27440
< 6.3.0
Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access
8.5HIGH
CVE-2025-27439
< 6.3.0
Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network acc
8.5HIGH
CVE-2025-0151
< 6.3.0
Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network acces
8.5HIGH
CVE-2025-0150
< 6.3.0
Incorrect behavior order in some Zoom Workplace Apps for iOS before version 6.3.0 may allow an authenticated user to conduct a den
7.1HIGH
CVE-2025-0149
< 6.3.0
Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of s
6.5MEDIUM
CVE-2024-27246
< 5.17.11
Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network acc
4.3MEDIUM
CVE-2024-27245
< 5.17.11
Buffer overflow in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network ac
4.3MEDIUM
CVE-2024-27239
< 5.17.11
Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network acc
4.3MEDIUM
CVE-2024-45426
< 6.1.0
Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via ne
4.9MEDIUM
CVE-2024-45425
< 6.1.0
Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network
4.9MEDIUM
CVE-2024-45424
< 6.1.0
Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via netw
5.3MEDIUM
CVE-2024-45421
< 6.2.0
Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.
8.5HIGH
CVE-2025-0144
< 6.2.5
Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network access.
3.1LOW
CVE-2024-45422
< 6.2.0
Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service
6.5MEDIUM
CVE-2024-45420
< 6.2.0
Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a denial of se
4.3MEDIUM
CVE-2024-45419
< 6.2.0
Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network a
8.1HIGH
CVE-2024-42438
< 6.1.0
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct
6.5MEDIUM
CVE-2024-42437
< 6.1.0
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct
6.5MEDIUM
CVE-2024-42436
< 6.1.0
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct
6.5MEDIUM
CVE-2024-42435
< 6.1.0
Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged us
4.9MEDIUM
CVE-2024-42434
< 6.1.0
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to condu
4.9MEDIUM
CVE-2024-39825
< 6.0.0
Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privileg
8.5HIGH
CVE-2024-39824
< 6.1.0
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to condu
4.9MEDIUM
CVE-2024-39823
< 6.1.0
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to condu
4.9MEDIUM
CVE-2024-39822
< 6.0.12
Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated
6.5MEDIUM
CVE-2024-39818
< 6.0.0
Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosu
7.5HIGH
CVE-2024-27241
< 6.0.0
Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network ac
5.3MEDIUM
CVE-2024-27243
< 5.17.5
Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network
6.5MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin