CVE-2025-30669
Zoom VDI Client vulnerability analysis and mitigation

Overview

CVE-2025-30669 is an improper certificate validation vulnerability (CWE-295) affecting certain Zoom Clients that may allow an unauthenticated attacker to disclose sensitive information via adjacent network access. It was disclosed by Zoom Video Communications on November 13, 2025, under security bulletin ZSB-25044. Affected products include Zoom Workplace Desktop (Windows/Linux), Zoom Meeting SDK (Windows/Linux), and Zoom Workplace Virtual Desktop Infrastructure (Windows) in versions prior to 6.5.10 (or prior to 6.3.14 / between 6.4.10 and 6.4.12 for VDI). The CVSS v3.1 base score is 6.5 (Medium) per NVD, and 4.8 (Medium) per Zoom's own CNA assessment (Zoom Advisory).

Technical details

The vulnerability is classified as CWE-295 (Improper Certificate Validation), meaning the affected Zoom clients fail to properly verify TLS/SSL certificates during network communications. This flaw enables an attacker positioned on the same network segment (adjacent access) to perform a man-in-the-middle (MitM) attack — potentially by presenting a rogue or improperly validated certificate — to intercept communications without authentication. Attack patterns associated with this vulnerability include CAPEC-459 (Creating a Rogue Certification Authority Certificate) and CAPEC-475 (Signature Spoofing by Improper Validation). No user interaction is required per NVD's assessment, though Zoom's CNA scoring indicates user interaction may be a factor (Zoom Advisory).

Impact

Successful exploitation results in a high confidentiality impact — an attacker on the adjacent network could intercept and read sensitive data transmitted by the Zoom client, such as meeting content, authentication tokens, or other in-transit information. Integrity and availability are not affected by this vulnerability. The scope is limited to the local network segment, reducing the risk of broad internet-scale exploitation, but environments with shared or untrusted networks (e.g., corporate Wi-Fi, VDI environments) face elevated risk (Zoom Advisory).

Exploitability

There is no known public proof-of-concept exploit or evidence of in-the-wild exploitation for CVE-2025-30669 at this time. The EPSS score is extremely low at approximately 0.009%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Zoom Advisory).

Exploitation steps

  1. Reconnaissance: Identify targets running vulnerable Zoom Workplace Desktop, Meeting SDK, or VDI clients (versions below 6.5.10 on Windows/Linux, or VDI below 6.3.14 / between 6.4.10–6.4.12) on a shared or accessible network segment.
  2. Network Positioning: Gain a position on the same local network as the target (e.g., via ARP spoofing, rogue Wi-Fi access point, or compromised network device) to enable adjacent-network interception.
  3. Certificate Spoofing: Set up a rogue TLS endpoint presenting an improperly validated or self-signed certificate that the vulnerable Zoom client fails to reject due to the CWE-295 flaw.
  4. Traffic Interception: Redirect the victim's Zoom client traffic through the attacker-controlled endpoint, capturing plaintext or decrypted communications (e.g., meeting data, credentials, tokens) that the client transmits without proper certificate verification (Zoom Advisory).

Indicators of compromise

  • Network: Unexpected ARP table changes or ARP spoofing activity on the local network segment; TLS connections from Zoom clients to unrecognized or self-signed certificate endpoints; unusual DNS responses redirecting Zoom service domains.
  • Logs: TLS handshake errors or certificate warnings in Zoom client logs; network traffic logs showing Zoom client connections to unexpected IP addresses on standard HTTPS ports.
  • Process/Behavior: Zoom client establishing connections to IP addresses not associated with known Zoom infrastructure (e.g., outside Zoom's published IP ranges).

Mitigation and workarounds

Zoom has released patched versions addressing this vulnerability. Users should update to the following minimum versions: Zoom Workplace Desktop (Windows/Linux) version 6.5.10 or later; Zoom Meeting SDK (Windows/Linux) version 6.5.10 or later; Zoom Workplace VDI (Windows) version 6.3.14 or later (or 6.4.12 if on the 6.4.x branch). Updates are available at https://zoom.us/download. No configuration-based workaround is documented; upgrading is the recommended remediation. Organizations should also enforce network segmentation and monitor for ARP spoofing or rogue access points to reduce adjacent-network attack risk (Zoom Advisory).

Community reactions

Coverage of CVE-2025-30669 has been limited to routine vulnerability tracking and digest publications, with no notable researcher commentary or significant community discussion identified. The vulnerability was included in at least one weekly threat landscape digest (Hawk-Eye Digest) and tracked by standard vulnerability databases. No major media coverage or vendor statements beyond the official Zoom security bulletin have been observed.

Additional resources


SourceThis report was generated using AI

Related Zoom VDI Client vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-53412CRITICAL9.8
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:virtual_desktop_infrastructure:*:*:*:*:*:windows:*:*
NoYesJul 16, 2026
CVE-2025-64740HIGH7.8
  • Zoom VDI Client logoZoom VDI Client
  • cpe:2.3:a:zoom:virtual_desktop_infrastructure
NoYesNov 13, 2025
CVE-2025-64739HIGH7.5
  • Zoom Rooms logoZoom Rooms
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesNov 13, 2025
CVE-2025-62483HIGH7.5
  • Zoom Rooms logoZoom Rooms
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesNov 13, 2025
CVE-2026-53410HIGH7
  • Zoom Rooms logoZoom Rooms
  • cpe:2.3:a:zoom:virtual_desktop_infrastructure
NoYesJul 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management