CVE-2025-49457: Zoom Clients for Windows - Untrusted Search Path
Published Aug 12, 2025
·Updated
Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access
Affected Software
7 affected components
Zoom Zoom Client for Windows
Zoom Meeting Software Development Kit Windows<6.3.10
Zoom Rooms Windows<6.3.10
Zoom Rooms Controller Windows<6.3.10
Zoom Workplace Desktop Windows<6.3.10
Zoom Workplace Virtual Desktop Infrastructure Windows<6.1.16
Zoom Workplace Virtual Desktop Infrastructure Windows>=6.2.10<6.2.12
Event History
Aug 12, 2025
CVE Published
via MITRE·10:54 PM
Data Sourced
via MITRE·10:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-49457?
CVE-2025-49457 has a severity rating that indicates a high risk of privilege escalation for users of the affected Zoom Clients.
2
How do I fix CVE-2025-49457?
To fix CVE-2025-49457, ensure that you update your Zoom Client for Windows to the latest version provided by Zoom.
3
Who is affected by CVE-2025-49457?
Users of certain Zoom Clients for Windows are affected by CVE-2025-49457, particularly those with network access.
4
What type of vulnerability is CVE-2025-49457?
CVE-2025-49457 is classified as an untrusted search path vulnerability that can lead to escalation of privilege.
5
Can CVE-2025-49457 be exploited remotely?
Yes, CVE-2025-49457 can potentially be exploited by an unauthenticated user through network access.