Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.
History

Wed, 20 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Zoom
Zoom meeting Software Development Kit
Zoom rooms
Zoom rooms Controller
Zoom video Software Development Kit
Zoom workplace Desktop
Zoom workplace Virtual Desktop Infrastructure
CPEs cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:video_software_development_kit:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:windows:*:*
Vendors & Products Zoom
Zoom meeting Software Development Kit
Zoom rooms
Zoom rooms Controller
Zoom video Software Development Kit
Zoom workplace Desktop
Zoom workplace Virtual Desktop Infrastructure

Thu, 30 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jan 2025 20:00:00 +0000

Type Values Removed Values Added
Description Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.
Title Zoom Workplace Apps for Windows - Untrusted Search Path
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published: 2025-01-30T19:45:39.432Z

Updated: 2025-01-30T21:23:22.776Z

Reserved: 2024-12-23T21:42:54.089Z

Link: CVE-2025-0145

cve-icon Vulnrichment

Updated: 2025-01-30T21:23:18.810Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-30T20:15:34.547

Modified: 2025-08-20T12:38:30.887

Link: CVE-2025-0145

cve-icon Redhat

No data.