CVE-2025-64738: Zoom Workplace for macOS - External Control of File Name or Path
Published Nov 13, 2025
·Updated
External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of information via local access.
Affected Software
3 affected components
Zoom Workplace for macOS<6.5.10
Zoom Meeting Software Development Kit Macos<6.5.10
Zoom Workplace Desktop Macos<6.5.10
Event History
Nov 13, 2025
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64738?
CVE-2025-64738 is considered a moderate severity vulnerability due to its potential for information disclosure.
2
How do I fix CVE-2025-64738?
To remediate CVE-2025-64738, upgrade to Zoom Workplace for macOS version 6.5.10 or later.
3
Who is affected by CVE-2025-64738?
CVE-2025-64738 affects authenticated users of Zoom Workplace for macOS versions prior to 6.5.10.
4
What kind of vulnerability is CVE-2025-64738?
CVE-2025-64738 is an external control of file name or path vulnerability that can lead to information disclosure.
5
Can CVE-2025-64738 be exploited remotely?
No, CVE-2025-64738 requires local access for exploitation.