CVE-2025-49457
Zoom Client vulnerability analysis and mitigation

Overview

CVE-2025-49457 is an untrusted search path vulnerability (CWE-426) in certain Zoom Clients for Windows that may allow an unauthenticated attacker to conduct privilege escalation via network access. Disclosed on August 12, 2025, under Zoom Security Bulletin ZSB-25030, the vulnerability affects Zoom Workplace Desktop, Zoom Rooms, Zoom Rooms Controller, Zoom Meeting SDK, and Zoom Workplace VDI — all for Windows — in versions prior to 6.3.10 (with specific VDI version ranges). It carries a CVSS v3.1 base score of 8.8 (High) (Zoom Advisory).

Technical details

The vulnerability is classified as CWE-426 (Untrusted Search Path), mapped to MITRE ATT&CK technique T1574.007 (Path Interception by PATH Environment Variable) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths). An attacker with network access can exploit the Zoom client's reliance on an untrusted or attacker-controlled search path to load a malicious library or executable, effectively hijacking the application's execution flow. Exploitation requires user interaction (e.g., a user launching or interacting with the Zoom client), but no prior authentication or privileges are needed from the attacker's side (Zoom Advisory, ZeroPath Summary).

Impact

Successful exploitation results in privilege escalation on the affected Windows system, with high impact to confidentiality, integrity, and availability. An attacker could gain elevated access to the system, potentially enabling full system compromise, data exfiltration, installation of persistent malware, or lateral movement within a corporate network. The broad deployment of Zoom across enterprise environments significantly amplifies the potential attack surface (Zoom Advisory, Security Affairs).

Exploitation steps

  1. Reconnaissance: Identify target Windows systems running vulnerable Zoom client versions (Workplace Desktop, Rooms, Rooms Controller, Meeting SDK, or VDI prior to 6.3.10) using network scanning or asset inventory tools.
  2. Prepare malicious payload: Craft a malicious DLL or executable with the same name as a library or binary that the Zoom client searches for via an untrusted path (e.g., a directory writable by a lower-privileged user or a network share).
  3. Position the payload: Place the malicious file in a directory that appears earlier in the search path than the legitimate file location — this could be a writable local directory, a network share, or a path injected via environment variable manipulation.
  4. Trigger user interaction: Induce the target user to launch or interact with the Zoom client (e.g., via a meeting invite or social engineering), causing the application to search for and load the malicious file.
  5. Achieve privilege escalation: The Zoom client loads the attacker-controlled binary with elevated privileges, granting the attacker code execution at a higher privilege level than the initiating user (Zoom Advisory, ZeroPath Summary).

Indicators of compromise

  • Process: Unexpected DLLs or executables loaded by Zoom client processes (e.g., Zoom.exe, ZoomRooms.exe) from non-standard directories such as user-writable folders, temp directories, or network shares.
  • File System: Presence of suspicious DLL or executable files in directories that precede Zoom's installation directory in the system or user PATH; newly created files in %TEMP%, %APPDATA%, or other writable locations matching Zoom dependency names.
  • Logs: Windows Event Logs (Event ID 7045 or similar) showing new services or modules loaded from unexpected paths; Sysmon Event ID 7 (Image Loaded) entries for Zoom processes loading DLLs from non-standard locations.
  • Network: Outbound connections from Zoom client processes to unexpected external IP addresses or internal hosts not associated with Zoom infrastructure, potentially indicating post-exploitation activity.

Mitigation and workarounds

Zoom has released patched versions addressing this vulnerability. Users should update to the following minimum versions: Zoom Workplace Desktop 6.3.10 or later, Zoom Rooms 6.3.10 or later, Zoom Rooms Controller 6.3.10 or later, Zoom Meeting SDK 6.3.10 or later, and Zoom Workplace VDI 6.1.16 (for 6.1.x), 6.2.12 (for 6.2.x), or 6.3.10 (for 6.2.13+). Updates are available at https://zoom.us/download. No specific configuration-based workaround has been published; upgrading to a patched version is the recommended and primary remediation (Zoom Advisory).

Community reactions

The vulnerability received broad coverage from security media outlets including The Hacker News, Security Affairs, Cyber Insider, and Heise, with most framing it as a critical risk for enterprise Windows users given Zoom's widespread deployment (The Hacker News, Security Affairs). Social media discussion on Bluesky and Mastodon/Infosec.exchange highlighted the severity and urged immediate patching. The Western Australian Government's SOC issued an advisory (20250815002) recommending urgent action for affected Zoom products (WA SOC Advisory). Community sentiment was generally focused on the ease of exploitation relative to the high CVSS score and the large installed base of Zoom on Windows.

Additional resources


SourceThis report was generated using AI

Related Zoom Client vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-53412CRITICAL9.8
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:zoom:*:*:*:*:*:windows:*:*
NoYesJul 16, 2026
CVE-2025-49457HIGH8.8
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesAug 12, 2025
CVE-2025-58133HIGH7.5
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesOct 15, 2025
CVE-2025-49460HIGH7.5
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesSep 09, 2025
CVE-2025-49464MEDIUM6.5
  • NixOS logoNixOS
  • cpe:2.3:a:zoom:zoom:*:*:*:*:*:windows:*:*
NoYesJul 10, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management