CVE-2025-49460
Zoom Client vulnerability analysis and mitigation

Overview

CVE-2025-49460 is an argument injection vulnerability (also described as uncontrolled resource consumption) in certain Zoom Workplace Clients that allows an unauthenticated remote attacker to conduct a denial of service via network access. It was published on September 9, 2025, by Zoom under security bulletin ZSB-25033. Affected products include Zoom Workplace Desktop (Windows, macOS, Linux), Zoom Rooms (Windows, macOS, Android, iPadOS), Zoom Rooms Controller (Windows, macOS, Linux, Android), Zoom Meeting SDK (Windows, macOS, Linux, Android), Zoom Workplace for iOS, and Zoom Workplace Virtual Desktop Infrastructure (Windows) — all versions prior to 6.5.0 (VDI prior to 6.3.14 or 6.4.12). The vulnerability carries a CVSS v3.1 base score of 7.5 (High) per NVD, though ENISA's EUVD rates it 4.3 (Medium) using a different vector (Zoom Advisory, Zoom Bulletin).

Technical details

The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption) and involves argument injection in the network-facing components of Zoom Workplace Clients. An unauthenticated attacker can send specially crafted network requests that inject malicious arguments, causing the client to consume excessive resources and become unresponsive. No user interaction or authentication is required, and the attack vector is entirely network-based with low complexity. No public proof-of-concept code or detailed technical write-up has been identified at this time (Zoom Advisory, Zoom Bulletin).

Impact

Successful exploitation results in a denial of service condition affecting the availability of the Zoom Workplace Client on the targeted system. There is no impact on confidentiality or integrity — the vulnerability is limited to availability (CVSS A:H). Affected users would experience application crashes or unresponsiveness, disrupting communications and collaboration workflows, but no data exfiltration or code execution is expected (Zoom Advisory).

Mitigation and workarounds

Zoom has released patched versions addressing this vulnerability. Users should update to Zoom Workplace Desktop, Rooms, Rooms Controller, Meeting SDK, and Workplace (iOS) version 6.5.0 or later; Zoom Workplace VDI for Windows should be updated to 6.3.14 (for the 6.3.x branch) or 6.4.12 (for the 6.4.x branch) or later. Updates are available via the official Zoom download page at https://zoom.us/download. No configuration-based workaround has been published; upgrading is the recommended remediation (Zoom Advisory, Zoom Bulletin).

Community reactions

Coverage of CVE-2025-49460 was limited to routine security news aggregation. CyberSecurityNews and CyberPress reported on Zoom's September 2025 security update batch, noting the release of multiple patches. No notable researcher commentary, vendor statements beyond the official bulletin, or significant social media discussion has been identified for this specific CVE.

Additional resources


SourceThis report was generated using AI

Related Zoom Client vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-53412CRITICAL9.8
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:zoom:*:*:*:*:*:windows:*:*
NoYesJul 16, 2026
CVE-2025-49457HIGH8.8
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesAug 12, 2025
CVE-2025-58133HIGH7.5
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesOct 15, 2025
CVE-2025-49460HIGH7.5
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesSep 09, 2025
CVE-2025-49464MEDIUM6.5
  • NixOS logoNixOS
  • cpe:2.3:a:zoom:zoom:*:*:*:*:*:windows:*:*
NoYesJul 10, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management