
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49457 is an untrusted search path vulnerability (CWE-426) in certain Zoom Clients for Windows that may allow an unauthenticated attacker to conduct privilege escalation via network access. Disclosed on August 12, 2025, under Zoom Security Bulletin ZSB-25030, the vulnerability affects Zoom Workplace Desktop, Zoom Rooms, Zoom Rooms Controller, Zoom Meeting SDK, and Zoom Workplace VDI — all for Windows — in versions prior to 6.3.10 (with specific VDI version ranges). It carries a CVSS v3.1 base score of 8.8 (High) (Zoom Advisory).
The vulnerability is classified as CWE-426 (Untrusted Search Path), mapped to MITRE ATT&CK technique T1574.007 (Path Interception by PATH Environment Variable) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths). An attacker with network access can exploit the Zoom client's reliance on an untrusted or attacker-controlled search path to load a malicious library or executable, effectively hijacking the application's execution flow. Exploitation requires user interaction (e.g., a user launching or interacting with the Zoom client), but no prior authentication or privileges are needed from the attacker's side (Zoom Advisory, ZeroPath Summary).
Successful exploitation results in privilege escalation on the affected Windows system, with high impact to confidentiality, integrity, and availability. An attacker could gain elevated access to the system, potentially enabling full system compromise, data exfiltration, installation of persistent malware, or lateral movement within a corporate network. The broad deployment of Zoom across enterprise environments significantly amplifies the potential attack surface (Zoom Advisory, Security Affairs).
Zoom.exe, ZoomRooms.exe) from non-standard directories such as user-writable folders, temp directories, or network shares.%TEMP%, %APPDATA%, or other writable locations matching Zoom dependency names.Zoom has released patched versions addressing this vulnerability. Users should update to the following minimum versions: Zoom Workplace Desktop 6.3.10 or later, Zoom Rooms 6.3.10 or later, Zoom Rooms Controller 6.3.10 or later, Zoom Meeting SDK 6.3.10 or later, and Zoom Workplace VDI 6.1.16 (for 6.1.x), 6.2.12 (for 6.2.x), or 6.3.10 (for 6.2.13+). Updates are available at https://zoom.us/download. No specific configuration-based workaround has been published; upgrading to a patched version is the recommended and primary remediation (Zoom Advisory).
The vulnerability received broad coverage from security media outlets including The Hacker News, Security Affairs, Cyber Insider, and Heise, with most framing it as a critical risk for enterprise Windows users given Zoom's widespread deployment (The Hacker News, Security Affairs). Social media discussion on Bluesky and Mastodon/Infosec.exchange highlighted the severity and urged immediate patching. The Western Australian Government's SOC issued an advisory (20250815002) recommending urgent action for affected Zoom products (WA SOC Advisory). Community sentiment was generally focused on the ease of exploitation relative to the high CVSS score and the large installed base of Zoom on Windows.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."