CVE-2025-0146: Zoom Workplace app for macOS - Symlink Following
Published Jan 30, 2025
·Updated
Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via local access.
Affected Software
6 affected components
Zoom Workplace App<6.2.10
Zoom Meeting Software Development Kit Macos<6.2.10
Zoom Rooms Macos<6.2.10
Zoom Rooms Controller Macos<6.2.10
Zoom Video Software Development Kit Macos<6.2.10
Zoom Workplace Desktop Macos<6.2.10
Event History
Jan 30, 2025
CVE Published
via MITRE·07:47 PM
Data Sourced
via MITRE·07:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0146?
CVE-2025-0146 is classified as a denial of service vulnerability due to symlink following in the installer for Zoom Workplace App.
2
How do I fix CVE-2025-0146?
To fix CVE-2025-0146, update the Zoom Workplace App to version 6.2.10 or later.
3
Who is affected by CVE-2025-0146?
Authenticated users of the Zoom Workplace App for macOS versions prior to 6.2.10 are affected by CVE-2025-0146.
4
What is the impact of CVE-2025-0146?
The impact of CVE-2025-0146 is a potential denial of service, which allows users with local access to disrupt the application.
5
Is there a workaround for CVE-2025-0146?
Currently, the best workaround for CVE-2025-0146 is to avoid using the vulnerable versions of the Zoom Workplace App until it is updated.