CVE-2025-64739: Zoom Clients - External Control of File Name or Path
Published Nov 13, 2025
·Updated
External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.
Affected Software
15 affected components
Zoom Zoom Client
Zoom Meeting Software Development Kit Linux<6.5.10
Zoom Meeting Software Development Kit Macos<6.5.10
Zoom Meeting Software Development Kit Windows<6.5.10
Zoom Rooms Iphone Os<6.5.10
Zoom Rooms Macos<6.5.10
Zoom Rooms Windows<6.5.10
Zoom Rooms Controller Linux<6.5.10
Zoom Rooms Controller Macos<6.5.10
Zoom Rooms Controller Windows<6.5.10
Zoom Workplace Desktop Linux<6.5.10
Zoom Workplace Desktop Macos<6.5.10
Zoom Workplace Desktop Windows<6.5.10
Zoom Workplace Virtual Desktop Infrastructure Windows<6.3.14
Zoom Workplace Virtual Desktop Infrastructure Windows>=6.4.10<6.4.12
Event History
Nov 13, 2025
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64739?
CVE-2025-64739 is classified as a high severity vulnerability due to its potential for information disclosure.
2
How do I fix CVE-2025-64739?
To mitigate CVE-2025-64739, users should update their Zoom Clients to the latest version provided by Zoom.
3
What kind of information can be disclosed due to CVE-2025-64739?
CVE-2025-64739 may allow an unauthenticated user to access sensitive data through unauthorized file path disclosure.
4
Is CVE-2025-64739 exploitable over the network?
Yes, CVE-2025-64739 can be exploited via network access, making it a considerable risk for users.
5
Which versions of Zoom Clients are affected by CVE-2025-64739?
CVE-2025-64739 affects certain Zoom Client versions, and users are advised to verify if their version is listed in the security bulletin for specific details.