Untrusted Search Path Vulnerability in Zoom Clients for Windows
CVE-2025-49457
9.6CRITICAL
What is CVE-2025-49457?
A security vulnerability exists in certain Zoom Clients for Windows due to an untrusted search path issue. This flaw may permit an unauthenticated user to gain elevated privileges on the system by exploiting network access. Zoom has addressed this issue, and users are advised to update their clients to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
Zoom Clients for Windows Windows see references
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
