Fiche vulnérabilité
CVE-2025-0145 : faille élevée zoom meeting software development kit (CVSS 7.8)
Description
Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 30 janv. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- zoom meeting software development kit
- zoom rooms
- zoom rooms controller
- zoom video software development kit
- zoom workplace desktop
- zoom workplace virtual desktop infrastructure