CVE-2025-30667: Zoom Workplace Apps - NULL Pointer Dereference
Published May 14, 2025
·Updated
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
Affected Software
22 affected components
Zoom Workplace Apps
Zoom Meeting Software Development Kit Android<6.4.0
Zoom Meeting Software Development Kit Iphone Os<6.4.0
Zoom Meeting Software Development Kit Linux<6.4.0
Zoom Meeting Software Development Kit Macos<6.4.0
Zoom Meeting Software Development Kit Windows<6.4.0
Zoom Rooms Android<6.4.0
Zoom Rooms Ipados<6.4.0
Zoom Rooms Macos<6.4.0
Zoom Rooms Windows<6.4.0
Zoom Rooms Controller Android<6.4.0
Zoom Rooms Controller Linux<6.4.0
Zoom Rooms Controller Macos<6.4.0
Zoom Rooms Controller Windows<6.4.0
Zoom Workplace Android<6.4.0
Zoom Workplace Iphone Os<6.4.0
Zoom Workplace Desktop Linux<6.4.0
Zoom Workplace Desktop Macos<6.4.0
Zoom Workplace Desktop Windows<6.4.0
Zoom Workplace Virtual Desktop Infrastructure Windows<6.1.17
Zoom Workplace Virtual Desktop Infrastructure Windows>=6.1.18<6.2.13
Zoom Workplace Virtual Desktop Infrastructure Windows>=6.2.14<6.3.10
Event History
May 14, 2025
CVE Published
via MITRE·05:36 PM
Data Sourced
via MITRE·05:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-30667?
CVE-2025-30667 is classified as a denial of service vulnerability.
2
How do I fix CVE-2025-30667?
To mitigate CVE-2025-30667, update the Zoom Workplace Apps to the latest version provided by Zoom.
3
What causes the CVE-2025-30667 vulnerability?
CVE-2025-30667 is caused by a NULL pointer dereference in the Zoom Workplace Apps for Windows.
4
Who is affected by CVE-2025-30667?
CVE-2025-30667 affects authenticated users of Zoom Workplace Apps on Windows.
5
What impact does CVE-2025-30667 have?
The impact of CVE-2025-30667 is a denial of service, which can disrupt the application's functionality.