Where
-Infinity
0
Severity
7
Race Condition
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

First published (updated )
Severity
9.8
Input Validation
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.

First published (updated )
Severity
8.8
EPSS
0.05%
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

First published (updated )
Severity
8.8
EPSS
0.05%
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

First published (updated )
Severity
5.2
XSS
AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

First published (updated )
Severity
5.2
XSS
AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

First published (updated )
Severity
7.8
EPSS
0.01%
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

First published (updated )
Severity
7.8
EPSS
0.01%
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

First published (updated )
Severity
9.8
EPSS
0.06%
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.

First published (updated )
Severity
6.5
Buffer Overflow
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access.

First published (updated )
Severity
8.8
Race Condition
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.

First published (updated )
Severity
8.2
XSS
AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.

First published (updated )
Severity
9.6
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

First published (updated )
Severity
6.5
Command Injection
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N

Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.

First published (updated )
Severity
6.5
AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.

First published (updated )
Severity
6.1
XSS
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203