CVE-2025-27443: Zoom Workplace Apps for Windows - Insecure Default Variable Initialization
Published Apr 8, 2025
·Updated
Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access.
Affected Software
5 affected components
Zoom Workplace Apps for Windows
Zoom Meeting Software Development Kit Windows<6.3.10
Zoom Rooms Windows<6.4.0
Zoom Rooms Controller Windows<6.4.0
Zoom Workplace Desktop Windows<6.3.10
Event History
Apr 8, 2025
CVE Published
via MITRE·04:16 PM
Data Sourced
via MITRE·04:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27443?
CVE-2025-27443 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-27443?
To fix CVE-2025-27443, update to the latest version of Zoom Workplace Apps for Windows where the issue is resolved.
3
What type of vulnerability is CVE-2025-27443?
CVE-2025-27443 is an insecure default variable initialization vulnerability.
4
Who is affected by CVE-2025-27443?
Authenticated users of Zoom Workplace Apps for Windows may be affected by CVE-2025-27443.
5
What impact does CVE-2025-27443 have?
CVE-2025-27443 may allow an authenticated user to conduct a loss of integrity via local access.