Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14914 | Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. |
| Link | Providers |
|---|---|
| https://www.zoom.com/en/trust/security-bulletin/zsb-25017 |
|
Thu, 06 Nov 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zoom
Zoom meeting Software Development Kit Zoom rooms Zoom rooms Controller Zoom workplace Zoom workplace Desktop Zoom workplace Virtual Desktop Infrastructure |
|
| CPEs | cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:android:*:* cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:linux:*:* cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:android:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:ipados:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:android:*:* cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:linux:*:* cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:workplace:*:*:*:*:*:android:*:* cpe:2.3:a:zoom:workplace:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:linux:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:windows:*:* |
|
| Vendors & Products |
Zoom
Zoom meeting Software Development Kit Zoom rooms Zoom rooms Controller Zoom workplace Zoom workplace Desktop Zoom workplace Virtual Desktop Infrastructure |
Thu, 02 Oct 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-74 |
Thu, 02 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. |
| Title | Zoom Workplace Apps - Improper Neutralization of Special Elements | Zoom Workplace Apps - Cross-site Scripting |
| Weaknesses | CWE-79 |
Wed, 14 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 May 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Title | Zoom Workplace Apps - Improper Neutralization of Special Elements | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zoom
Published:
Updated: 2026-02-26T18:28:08.837Z
Reserved: 2025-03-24T22:35:25.475Z
Link: CVE-2025-30664
Updated: 2025-05-14T18:58:56.464Z
Status : Analyzed
Published: 2025-05-14T18:15:30.180
Modified: 2025-11-06T15:39:58.980
Link: CVE-2025-30664
No data.
OpenCVE Enrichment
No data.
EUVD