Critical Security Flaws Found in Zoom Workplace Apps Across All Major Platforms
Zoom Video Communications has uncovered a series of security vulnerabilities affecting its Workplace Apps on Windows, macOS, Linux, iOS, and Android. These flaws open the door to a range of cybersecurity threats, from system crashes to unauthorized privilege escalation and remote code execution.
What’s at Risk?
Among the most serious issues is a race condition vulnerability—a classic time-of-check to time-of-use (TOCTOU) flaw—identified as CVE-2025-30663. Rated 5.9 on the CVSS 4.0 scale, this bug allows local attackers to exploit timing mismatches between system checks and actual operations. The result? A pathway for privilege escalation and potential access to sensitive data.
Though attackers need to be authenticated users with access to the system, the implications are significant—especially for enterprise environments where even local exploits can lead to broader compromise.
Additional Threat Vectors
Zoom’s disclosure also includes multiple NULL pointer dereference vulnerabilities (CVE-2025-30665 through CVE-2025-30668). If exploited, these flaws can crash applications or, worse, provide a foothold for executing arbitrary code or launching denial-of-service (DoS) attacks.
These bugs vary in severity but collectively highlight the importance of rapid patch deployment and strong endpoint monitoring in organizations relying on Zoom’s ecosystem.
Why It Matters
While none of these vulnerabilities are being actively exploited at the time of disclosure, they represent clear opportunities for adversaries—especially in hybrid work environments where endpoint security can vary widely. Organizations are advised to apply patches immediately and audit systems for potential exposure.
Security Weaknesses in Zoom Workplace Apps
A recent analysis has revealed a series of vulnerabilities affecting Zoom Workplace Apps across multiple platforms, with potential consequences ranging from system instability to unauthorized access. Below is a breakdown of the issues disclosed:
| CVE Identifier | Impacted Platforms | Issue Overview |
|---|---|---|
| CVE-2025-46785 | Windows Only | A buffer over-read vulnerability enables unauthorized memory access, potentially exposing sensitive data or causing system crashes. |
| CVE-2025-30668 | Windows Only | A flaw in memory handling (NULL pointer dereference) can result in application failure or may be exploited to execute arbitrary code. |
| CVE-2025-30667 | All Platforms | An unchecked NULL pointer reference introduces a risk of denial-of-service (DoS) and could lead to arbitrary code execution across operating systems. |
| CVE-2025-30665 | Windows Only | A Windows-specific issue with pointer dereferencing creates a pathway for app crashes and potential privilege escalation. |
| CVE-2025-30666 | Windows Only | Another instance of a NULL pointer vulnerability, closely related to CVE-2025-30665, further increasing the risk of app instability. |
| CVE-2025-30664 | All Platforms | Inadequate input validation may allow attackers to inject malicious content, potentially bypassing core security mechanisms. |
| CVE-2025-30663 | All Platforms | A race condition due to time-of-check/time-of-use (TOCTOU) flaws poses a high-severity threat, giving local attackers an opportunity to escalate privileges. |
Zoom Rolls Out Patches for Critical Vulnerabilities Across Its Workplace Suite
Zoom has issued fixes for a range of newly identified vulnerabilities that could allow attackers to bypass key security mechanisms, access protected memory, or disrupt application stability across its suite of Workplace Apps.
Two Notable Flaws
- CVE-2025-30664: A critical weakness in how the apps process user input allows for the injection of malicious content. By exploiting improperly sanitized data fields, attackers could sneak past standard security filters.
- CVE-2025-46785: Found in the Windows version of the Zoom Workplace App, this bug involves unsafe memory access. Improper buffer management can lead to the exposure of sensitive information or result in unstable app behavior.
Products at Risk
These vulnerabilities affect a broad spectrum of Zoom’s ecosystem. Devices and environments running outdated versions are especially exposed. Affected products include:
- Zoom Workplace for Windows (prior to 6.4.0 62047)
- Zoom Workplace for macOS (prior to 6.3.11 50104)
- Zoom Workplace for Linux (prior to 6.3.11 7212)
- Virtual Desktop Infrastructure (VDI) clients (6.1.0 – 6.2.12.25780)
- Zoom Rooms – Controllers and Clients
- Zoom Meeting SDK – All major platforms: Windows, macOS, Linux, iOS, and Android
What You Should Do
Although Zoom hasn’t detailed individual customer impact, the company urges all users to upgrade immediately. The official advisory stresses that the most recent versions include critical security enhancements designed to neutralize these vulnerabilities.
“We recommend users update to the latest version of Zoom software to get the latest fixes and security improvements,” the company stated.
Expert Guidance
Cybersecurity professionals echo this advice, particularly for enterprise and high-security environments. Privilege escalation and input injection flaws can be leveraged for broader network compromise if left unaddressed.
To stay protected:
- Enable automatic updates within the Zoom app settings
- Or manually download the latest versions from Zoom’s official download page
Proactive patching is the simplest way to stay ahead of evolving threats in today’s hybrid work landscape.




