Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14915 | Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access. |
| Link | Providers |
|---|---|
| https://www.zoom.com/en/trust/security-bulletin/zsb-25022 |
|
Thu, 06 Nov 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zoom
Zoom meeting Software Development Kit Zoom rooms Zoom rooms Controller Zoom workplace Zoom workplace Desktop Zoom workplace Virtual Desktop Infrastructure |
|
| CPEs | cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:android:*:* cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:linux:*:* cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:android:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:ipados:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:android:*:* cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:linux:*:* cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:workplace:*:*:*:*:*:android:*:* cpe:2.3:a:zoom:workplace:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:linux:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:windows:*:* |
|
| Vendors & Products |
Zoom
Zoom meeting Software Development Kit Zoom rooms Zoom rooms Controller Zoom workplace Zoom workplace Desktop Zoom workplace Virtual Desktop Infrastructure |
Thu, 02 Oct 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-74 |
Thu, 02 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access. | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access. |
| Title | Zoom Workplace Apps - Improper Neutralization of Special Elements | Zoom Workplace Apps - Cross-site Scripting |
| Weaknesses | CWE-79 |
Wed, 14 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access. | |
| Title | Zoom Workplace Apps - Improper Neutralization of Special Elements | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zoom
Published:
Updated: 2025-10-02T20:59:29.011Z
Reserved: 2025-04-29T21:24:03.394Z
Link: CVE-2025-46786
Updated: 2025-05-14T18:58:47.838Z
Status : Analyzed
Published: 2025-05-14T18:15:31.303
Modified: 2025-11-06T19:51:11.923
Link: CVE-2025-46786
No data.
OpenCVE Enrichment
No data.
EUVD