Cross Site Scripting Vulnerability in Zoom Workplace Apps by Zoom
CVE-2025-27442
4.6MEDIUM
Summary
A vulnerability exists in Zoom Workplace Apps that allows an unauthenticated user to potentially manipulate application integrity through cross site scripting. This security flaw can be exploited by individuals with access to adjacent networks, leading to unauthorized actions or the exposure of sensitive information. Organizations using these applications should assess their security posture and apply any recommended patches to mitigate risks associated with this vulnerability.
Affected Version(s)
Zoom Workplace Apps Windows See references.
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved