CVE-2025-58132: Zoom Clients for Windows - Command Injection
Published Oct 15, 2025
·Updated
Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.
Affected Software
6 affected components
Zoom Zoom Client for Windows
Zoom Meeting Software Development Kit Windows<6.5.5
Zoom Rooms Windows<6.5.5
Zoom Workplace Desktop Windows<6.5.5
Zoom Workplace Virtual Desktop Infrastructure Windows<6.3.15
Zoom Workplace Virtual Desktop Infrastructure Windows>=6.4.0<6.4.13
Event History
Oct 15, 2025
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-58132?
CVE-2025-58132 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-58132?
To fix CVE-2025-58132, update your Zoom Client for Windows to the latest version as provided by Zoom.
3
Who is affected by CVE-2025-58132?
CVE-2025-58132 affects authenticated users of the Zoom Client for Windows.
4
What type of vulnerability is CVE-2025-58132?
CVE-2025-58132 is a command injection vulnerability that may lead to information disclosure.
5
Can CVE-2025-58132 be exploited remotely?
CVE-2025-58132 requires authenticated access, making it potentially exploitable by users with network access.