← Back

CVE-2025-27442

nvd nist
Published: Apr 8, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.2
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.1 / Impact: 2.7
Source: NVD

Description

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

Affected (20)

6 products
Meeting Software Development Kit
Rooms
Rooms Controller
Workplace
Workplace Desktop
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Zoom
Before 6.3.0
Before 6.3.10
Before 6.3.0
Before 6.3.0
Before 6.3.10
Zoom
Before 6.4.0
Before 6.4.0
Before 6.4.0
Before 6.4.0
Zoom
Before 6.4.0
Before 6.4.0
Before 6.4.0
Before 6.4.0
Zoom
Before 6.3.10
Before 6.3.10
Zoom
Before 6.3.10
Before 6.3.10
Before 6.3.10
Zoom
Before 6.1.16
From 6.1.17 to 6.2.12

References (1)

Source: security@zoom.us
Vendor Advisory

Timeline

No history available yet.