CVE-2025-0146

Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via local access.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:video_software_development_kit:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:*

History

01 Aug 2025, 01:25

Type Values Removed Values Added
First Time Zoom rooms
Zoom rooms Controller
Zoom workplace Desktop
Zoom
Zoom meeting Software Development Kit
Zoom video Software Development Kit
Summary
  • (es) El enlace simbólico que sigue en el instalador de la aplicación Zoom Workplace para macOS anterior a la versión 6.2.10 puede permitir que un usuario autenticado realice una denegación de servicio a través del acceso local.
CPE cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:video_software_development_kit:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:*
References () https://www.zoom.com/en/trust/security-bulletin/zsb-25005/ - () https://www.zoom.com/en/trust/security-bulletin/zsb-25005/ - Vendor Advisory

30 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 20:15

Updated : 2025-08-01 01:25


NVD link : CVE-2025-0146

Mitre link : CVE-2025-0146

CVE.ORG link : CVE-2025-0146


JSON object : View

Products Affected

zoom

  • video_software_development_kit
  • rooms_controller
  • meeting_software_development_kit
  • workplace_desktop
  • rooms
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')