CVE-2025-0144: Zoom Workplace Apps - Out-of-bounds Write
Published Jan 30, 2025
·Updated
Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network access.
Affected Software
25 affected components
Zoom Workplace Apps
Zoom Meeting Software Development Kit Android<6.2.5
Zoom Meeting Software Development Kit Iphone Os<6.2.5
Zoom Meeting Software Development Kit Linux<6.2.5
Zoom Meeting Software Development Kit Macos<6.2.5
Zoom Meeting Software Development Kit Windows<6.2.5
Zoom Rooms Ipados<6.2.5
Zoom Rooms Macos<6.2.5
Zoom Rooms Windows<6.2.5
Zoom Rooms Controller Android<6.2.5
Zoom Rooms Controller Linux<6.2.5
Zoom Rooms Controller Macos<6.2.5
Zoom Rooms Controller Windows<6.2.5
Zoom Video Software Development Kit Android<6.2.5
Zoom Video Software Development Kit Iphone Os<6.2.5
Zoom Video Software Development Kit Linux<6.2.5
Zoom Video Software Development Kit Macos<6.2.5
Zoom Video Software Development Kit Windows<6.2.5
Zoom Workplace Android<6.2.5
Zoom Workplace Iphone Os<6.2.5
Zoom Workplace Desktop Linux<6.2.5
Zoom Workplace Desktop Macos<6.2.5
Zoom Workplace Desktop Windows<6.2.5
Zoom Workplace Virtual Desktop Infrastructure Windows<6.0.15
Zoom Workplace Virtual Desktop Infrastructure Windows>=6.0.16<6.1.13
Event History
Jan 30, 2025
CVE Published
via MITRE·07:44 PM
Data Sourced
via MITRE·07:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0144?
CVE-2025-0144 is considered a critical vulnerability due to its potential to allow loss of integrity.
2
How do I fix CVE-2025-0144?
To fix CVE-2025-0144, update your Zoom Workplace Apps to the latest version provided by Zoom.
3
Who is affected by CVE-2025-0144?
CVE-2025-0144 affects authorized users of Zoom Workplace Apps.
4
What impact does CVE-2025-0144 have?
CVE-2025-0144 can lead to a loss of integrity due to an out-of-bounds write.
5
When was CVE-2025-0144 reported?
CVE-2025-0144 was disclosed in 2025 and should be addressed promptly by affected users.