[CIVN-2025-0261] Multiple vulnerabilities in Zoom Products

By Published On: October 17, 2025

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple vulnerabilities in Zoom Products 
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: MEDIUM
Software Affected
Zoom Rooms for Windows prior to version 6.5.1
Zoom Rooms for macOS prior to version 6.5.1
Zoom Rooms for Android prior to version 6.5.1
Zoom Rooms for iOS prior to version 6.5.1
Zoom Rooms for iPad prior to version 6.5.1
Zoom Workplace for Windows prior to version 6.5.5
Zoom Workplace VDI Client for Windows prior to versions 6.3.15 and 6.4.13 (respective tracks)
Zoom Meeting SDK for Windows prior to version 6.5.5
Overview
Multiple vulnerabilities have been reported in Zoom products that could allow a remote attacker to execute arbitrary commands, disclose sensitive information, or gain unauthorized access to meeting and configuration data.
Target Audience:
All end-user organisations and individuals using Zoom applications.
Risk Assessment:
Information disclosure or partial compromise of user sessions.
Impact Assessment:
Potential for unauthorized access to meeting or configuration data, disclosure of sensitive session information, compromise of session integrity or limited privilege escalation.
Description
Multiple vulnerabilities exist in Zoom products due to improper input sanitization and inadequate session validation.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary commands, disclose sensitive information, or gain unauthorized access to meeting and configuration data.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.zoom.com/en/trust/security-bulletin/zsb-25038/
https://www.zoom.com/en/trust/security-bulletin/zsb-25039/
References
Zoom
https://www.zoom.com/en/trust/security-bulletin/zsb-25038/
https://www.zoom.com/en/trust/security-bulletin/zsb-25039/
CVE Name
CVE-2025-58132
CVE-2025-58133
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmjyH9QACgkQ3jCgcSdc
ys/8jw//bS4QTgMF2ixIb875mx01DIoGhub0c7HvbE6DYnEB5zYtf1T+qQF4bcDn
Z6Jm/HyM39bmnnB52DIpekONIf8eGAypahAJCSHCdgOmk78GqB3F1+eZSSEYyr5r
Tar57vjbx2RGr4G/iaHN81jebS1uoUA0ZGgUeUdDo1VpdIpj+McAcQHJm0sUco5i
zB5Cx0CvsoTez95aSN8lNLOc5ra6sCAFc3wxTSTM9uIGlnlzhvkWm1znoZy/N9YN
AW9f/paXKzKyszlkYaMKRnnWhUf/Y7TkutQFe2S+YKaRKrZxwRWvXVYrz3eQ27cb
F5uT9rF6XrxMFezFOwgzsL75rOVSddmmoK1/VjCISsieHwh5VkEvdpvkTv32LZBk
Wc3AxZpRaJ3zmynZAWwpTSgaLSQlYQlO6AABmGyA6KI7hivBFWeT1GzHAtv7tUSS
AXiaFQG4P2YO8HR6KTl7B/R43BQSgKK340340VxAqSXU2Wb7pavjL467qZnxle4o
AlRsfCp0fGtTFXuuYInROx8nINn/9MYYFfWrY7krk5EMnsHVzX6PbjRsvNboReoV
YylGIC8bOLe5nwG+loikGEL5mxK3srcpV//AKiVmRt9H0dR+FJ2VnXsVe7ehJK/a
OMOOwPMasBIltqI9Mlfm9HlABP3yDa8qHWD3GcSxp7XorozpFx8=
=eHhK
—–END PGP SIGNATURE—–

Share this article