Новости компьютерной безопасности:

  Latest News

Zoom Workplace for Windows Vulnerability Allow Users to Escalate Privilege

С сайта: Vulnerability(cybersecuritynews.com)

Zoom Workplace for Windows Vulnerability Allow Users to Escalate Privilege

Author: Abinaya

A security vulnerability has been discovered in Zoom Workplace VDI Client for Windows that could allow attackers to gain elevated privileges on affected systems.

The flaw, tracked as CVE-2025-64740, has been assigned a high severity rating with a CVSS score of 7.5, according to Zoom’s security bulletin ZSB-25042.

The vulnerability stems from improper verification of cryptographic signatures in the Zoom Workplace VDI Client for Windows installer.

This weakness can be exploited by an authenticated user with local access to escalate their privileges on the system.

Zoom Workplace for Windows Vulnerability
When successfully exploited, attackers could gain higher-level permissions, potentially executing unauthorized commands, accessing sensitive data, or compromising system integrity.

The security flaw affects Zoom Workplace VDI Client for Windows versions before 6.3.14, 6.4.12, and 6.5.10 in their respective tracks.

While the vulnerability requires local access and user interaction, making it somewhat complex to exploit, the potential impact remains significant.

The CVSS vector string indicates it can affect confidentiality, integrity, and availability of the compromised system.

BulletinCVE IDCVSS ScoreCVSS VectorAffected ProductsZSB-25042CVE-2025-647407.5CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:HZoom Workplace VDI Client for Windows before versions 6.3.14, 6.4.12 and 6.5.10
Privilege escalation vulnerabilities are particularly concerning in enterprise environments where Zoom is widely deployed for remote work and virtual desktop infrastructure.

Attackers who already have limited access to a system could exploit this flaw to gain administrative rights, bypass security controls, and potentially move laterally across networks to compromise additional resources.

The improper cryptographic signature verification means the installer cannot properly validate whether the software being installed is legitimate or has been corrupted.

This creates an opportunity for threat actors to manipulate the installation process and inject malicious code with elevated permissions.

Zoom has released security updates to address this vulnerability and strongly recommends that all users update their Zoom Workplace VDI Client for Windows immediately.

Organizations using affected versions should prioritize patching to mitigate the risk of exploitation. Users can download the latest secure versions from Zoom’s official download page at zoom.us/download.

System administrators should verify that all installations across their organization are updated to versions 6.3.14, 6.4.12, 6.5.10, or later, depending on their deployment track.

This disclosure underscores the importance of maintaining up-to-date software, especially for widely used communication platforms in enterprise settings.



#Cyber_Security_News #Latest_Cybersecurity_News #Vulnerability #Windows #Zoom #cyber_security #cyber_security_news #vulnerability

Оригинальная версия на сайте: Zoom Workplace for Windows Vulnerability Allow Users to Escalate Privilege
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.