Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24529 | Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access |
| Link | Providers |
|---|---|
| https://www.zoom.com/en/trust/security-bulletin/zsb-25030 |
|
Mon, 08 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zoom meeting Software Development Kit
Zoom rooms Zoom rooms Controller Zoom workplace Desktop Zoom workplace Virtual Desktop Infrastructure |
|
| CPEs | cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:windows:*:* |
|
| Vendors & Products |
Zoom meeting Software Development Kit
Zoom rooms Zoom rooms Controller Zoom workplace Desktop Zoom workplace Virtual Desktop Infrastructure |
Thu, 14 Aug 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zoom
Zoom zoom Zoom zoom Client |
|
| Vendors & Products |
Zoom
Zoom zoom Zoom zoom Client |
Wed, 13 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 Aug 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access | |
| Title | Zoom Clients for Windows - Untrusted Search Path | |
| Weaknesses | CWE-426 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zoom
Published:
Updated: 2026-02-26T17:48:42.934Z
Reserved: 2025-06-04T22:48:18.920Z
Link: CVE-2025-49457
Updated: 2025-08-13T14:14:30.748Z
Status : Analyzed
Published: 2025-08-12T23:15:28.243
Modified: 2025-09-08T15:44:28.283
Link: CVE-2025-49457
No data.
OpenCVE Enrichment
Updated: 2025-08-13T21:47:53Z
EUVD