Wednesday, 09 July 2025

Zoom fixes several dangerous vulnerabilities

Popular video conferencing service Zoom has resolved 6 security vulnerabilities (CVE-2025-0142, CVE-2025-0143, CVE-2025-0144, CVE-2025-0145, CVE-2025-0146, CVE-2025-0147) in Zoom products. A malicious actor could exploit some of these vulnerabilities to trigger sensitive information disclosure, elevation of privilege and denial of service condition on the targeted system. Issues affect:

  • Zoom Jenkins bot plugin before version 1.6;

  • Zoom Workplace App for Linux before version 6.2.5;

  • Zoom Meeting SDK for Linux before version 6.2.5;

  • Zoom Video SDK for Linux before version 6.2.5;

  • Zoom Workplace App for Windows before version 6.2.5;

  • Zoom Workplace App for macOS before version 6.2.5 and 6.2.10;

  • Zoom Workplace App for Linux before version 6.2.5 and 6.2.10;

  • Zoom Workplace App for iOS before version 6.2.5;

  • Zoom Workplace App for Android before version 6.2.5;

  • Zoom Workplace VDI Client for Windows before version 6.1.13 (except version 6.0.15);

  • Zoom Rooms Client for Windows before version 6.2.5;

  • Zoom Rooms Client for macOS before version 6.2.5 and 6.2.10;

  • Zoom Rooms Client for iPad before version 6.2.5;

  • Zoom Rooms Controller for Windows before version 6.2.5;

  • Zoom Rooms Controller for macOS before version 6.2.5 and 6.2.10;

  • Zoom Rooms Controller for Linux before version 6.2.5;

  • Zoom Rooms Controller for Android before version 6.2.5;

  • Zoom Meeting SDK for Windows before version 6.2.5;

  • Zoom Meeting SDK for iOS before version 6.2.5;

  • Zoom Meeting SDK for Android before version 6.2.5;

  • Zoom Meeting SDK for macOS before version 6.2.5 and 6.2.10;

  • Zoom Meeting SDK for Linux before version 6.2.5 and 6.2.10;

  • Zoom Video SDK for Windows before version 6.2.5;

  • Zoom Video SDK for macOS before version 6.2.5 and 6.2.10;

  • Zoom Video SDK for Android before version 6.2.5;

  • Zoom Video SDK for iOS before version 6.2.5;

  • Zoom Video SDK for Linux before version 6.2.5 and 6.2.10;

More information on vulnerabilities and updates is available in Zoom security bulletins – zoom.us

20 January 2025

-
21