Privilege Escalation Vulnerabilities Found in Zoom Workplace Apps

Privilege Escalation Vulnerabilities Found in Zoom Workplace Apps

Critical Security Flaws Found in Zoom Workplace Apps Across All Major Platforms

Zoom Video Communications has uncovered a series of security vulnerabilities affecting its Workplace Apps on Windows, macOS, Linux, iOS, and Android. These flaws open the door to a range of cybersecurity threats, from system crashes to unauthorized privilege escalation and remote code execution.

What’s at Risk?

Among the most serious issues is a race condition vulnerability—a classic time-of-check to time-of-use (TOCTOU) flaw—identified as CVE-2025-30663. Rated 5.9 on the CVSS 4.0 scale, this bug allows local attackers to exploit timing mismatches between system checks and actual operations. The result? A pathway for privilege escalation and potential access to sensitive data.

Though attackers need to be authenticated users with access to the system, the implications are significant—especially for enterprise environments where even local exploits can lead to broader compromise.

Additional Threat Vectors

Zoom’s disclosure also includes multiple NULL pointer dereference vulnerabilities (CVE-2025-30665 through CVE-2025-30668). If exploited, these flaws can crash applications or, worse, provide a foothold for executing arbitrary code or launching denial-of-service (DoS) attacks.

These bugs vary in severity but collectively highlight the importance of rapid patch deployment and strong endpoint monitoring in organizations relying on Zoom’s ecosystem.

Why It Matters

While none of these vulnerabilities are being actively exploited at the time of disclosure, they represent clear opportunities for adversaries—especially in hybrid work environments where endpoint security can vary widely. Organizations are advised to apply patches immediately and audit systems for potential exposure.

Security Weaknesses in Zoom Workplace Apps

A recent analysis has revealed a series of vulnerabilities affecting Zoom Workplace Apps across multiple platforms, with potential consequences ranging from system instability to unauthorized access. Below is a breakdown of the issues disclosed:

CVE IdentifierImpacted PlatformsIssue Overview
CVE-2025-46785Windows OnlyA buffer over-read vulnerability enables unauthorized memory access, potentially exposing sensitive data or causing system crashes.
CVE-2025-30668Windows OnlyA flaw in memory handling (NULL pointer dereference) can result in application failure or may be exploited to execute arbitrary code.
CVE-2025-30667All PlatformsAn unchecked NULL pointer reference introduces a risk of denial-of-service (DoS) and could lead to arbitrary code execution across operating systems.
CVE-2025-30665Windows OnlyA Windows-specific issue with pointer dereferencing creates a pathway for app crashes and potential privilege escalation.
CVE-2025-30666Windows OnlyAnother instance of a NULL pointer vulnerability, closely related to CVE-2025-30665, further increasing the risk of app instability.
CVE-2025-30664All PlatformsInadequate input validation may allow attackers to inject malicious content, potentially bypassing core security mechanisms.
CVE-2025-30663All PlatformsA race condition due to time-of-check/time-of-use (TOCTOU) flaws poses a high-severity threat, giving local attackers an opportunity to escalate privileges.

Zoom Rolls Out Patches for Critical Vulnerabilities Across Its Workplace Suite

Zoom has issued fixes for a range of newly identified vulnerabilities that could allow attackers to bypass key security mechanisms, access protected memory, or disrupt application stability across its suite of Workplace Apps.

Two Notable Flaws

  • CVE-2025-30664: A critical weakness in how the apps process user input allows for the injection of malicious content. By exploiting improperly sanitized data fields, attackers could sneak past standard security filters.
  • CVE-2025-46785: Found in the Windows version of the Zoom Workplace App, this bug involves unsafe memory access. Improper buffer management can lead to the exposure of sensitive information or result in unstable app behavior.

Products at Risk

These vulnerabilities affect a broad spectrum of Zoom’s ecosystem. Devices and environments running outdated versions are especially exposed. Affected products include:

  • Zoom Workplace for Windows (prior to 6.4.0 62047)
  • Zoom Workplace for macOS (prior to 6.3.11 50104)
  • Zoom Workplace for Linux (prior to 6.3.11 7212)
  • Virtual Desktop Infrastructure (VDI) clients (6.1.0 – 6.2.12.25780)
  • Zoom Rooms – Controllers and Clients
  • Zoom Meeting SDK – All major platforms: Windows, macOS, Linux, iOS, and Android

What You Should Do

Although Zoom hasn’t detailed individual customer impact, the company urges all users to upgrade immediately. The official advisory stresses that the most recent versions include critical security enhancements designed to neutralize these vulnerabilities.

“We recommend users update to the latest version of Zoom software to get the latest fixes and security improvements,” the company stated.

Expert Guidance

Cybersecurity professionals echo this advice, particularly for enterprise and high-security environments. Privilege escalation and input injection flaws can be leveraged for broader network compromise if left unaddressed.

To stay protected:

  • Enable automatic updates within the Zoom app settings
  • Or manually download the latest versions from Zoom’s official download page

Proactive patching is the simplest way to stay ahead of evolving threats in today’s hybrid work landscape.

More Articles & Posts