← Back

Zoom

zoom

232 CVEs • 62 products

Products (62)

Click to collapse
Toggle
Rooms
rooms
Zoom
zoom
Workplace
workplace
Meetings
meetings
Hybrid Mmr
hybrid_mmr
Hybrid Zproxy
hybrid_zproxy
Vdi Citrix
vdi_citrix
Vdi Vmware
vdi_vmware
Meeting Sdk
meeting_sdk
It Installer
it_installer
Chat
chat
Screen Sharing
screen_sharing
Cleanzoom
cleanzoom
Remote Control
remote_control
Poly Ccx 700
poly_ccx_700
Poly Ccx 600
poly_ccx_600
Yealink Vp59
yealink_vp59
Yealink Mp54
yealink_mp54
Yealink Mp56
yealink_mp56

CVEs (232)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zoom
1Zoom Client For Meetings
Jun 17, 2026
Nov 11, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a remote control request to a user in the process of in-meeting screen sharing. This could allow meeting...Show more
In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a remote control request to a user in the process of in-meeting screen sharing. This could allow meeting participants to be targeted for social engineering attacks.Show less
1Zoom
5Zoom On Premise Meeting Connector Controller
Zoom On Premise Meeting Connector MmrZoom On Premise Recording Connector+2 more
Jun 17, 2026
Nov 11, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector be...Show more
The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector before version 3.8.42.20200905, Zoom On-Premise Virtual Room Connector before version 4.4.6344.20200612, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5492.20200616 fails to validate that a NULL byte was sent while authenticating. This could lead to a crash of the login service.Show less
1Zoom
5Zoom On Premise Meeting Connector Controller
Zoom On Premise Meeting Connector MmrZoom On Premise Recording Connector+2 more
Jun 17, 2026
Nov 11, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Record...Show more
The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Recording Connector before version 3.8.45.20210703, Zoom On-Premise Virtual Room Connector before version 4.4.6868.20210703, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5496.20210703 fails to validate input sent in requests to set the network proxy password. This could lead to remote command injection by a web portal administrator.Show less
1Zoom
4Meeting Connector
Recording ConnectorVirtual Room Connector+1 more
Jun 17, 2026
Sep 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Rec...Show more
The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8.44.20210326, Zoom on-premise Virtual Room Connector before version 4.4.6752.20210326, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network configuration, which could lead to remote command injection on the on-premise image by the web portal administrators.Show less
1Zoom
1Meeting Connector
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, which leads to exhaustion of resources and s...Show more
The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, which leads to exhaustion of resources and system crash.Show less
1Zoom
4Meeting Connector
Recording ConnectorVirtual Room Connector+1 more
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meeting Connector MMR before version 4.6.348.20201217, Zoom on-premise Record...Show more
The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meeting Connector MMR before version 4.6.348.20201217, Zoom on-premise Recording Connector before version 3.8.42.20200905, Zoom on-premise Virtual Room Connector before version 4.4.6620.20201110, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network proxy configuration, which could lead to remote command injection on the on-premise image by a web portal administrator.Show less
1Zoom
1Zoom Plugin For Microsoft Outlook
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a Time-of-check Time-of-use (TOC/TOU) vulnerability during the plugin installation process. This could allow a standard user t...Show more
All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a Time-of-check Time-of-use (TOC/TOU) vulnerability during the plugin installation process. This could allow a standard user to write their own malicious application to the plugin directory, allowing the malicious application to execute in a privileged context.Show less
1Zoom
1Meetings
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCC...Show more
During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.Show less
1Zoom
1Rooms
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to launch Internet Explorer with elevated privileges. If the installer was launched with elevated privileg...Show more
During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to launch Internet Explorer with elevated privileges. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.Show less
1Zoom
1Zoom Plugin For Microsoft Outlook
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A user-writable application bundle unpacked during the install for all versions of the Zoom Plugin for Microsoft Outlook for Mac before 5.0.25611.0521 allows for privilege escalation to root.
1Zoom
3Meetings
RoomsScreen Sharing
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, a...Show more
It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts to a user-writable directory. In the affected products listed below, a malicious actor with local access to a user's machine could use this flaw to potentially run arbitrary system commands in a higher privileged context during the installation process.Show less
1Zoom
1Meetings
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for poten...Show more
The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the user writable directory used and a non-user writable directory.Show less
1Zoom
1Meetings
Jun 17, 2026
Sep 27, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code...Show more
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context.Show less
1Zoom
1Chat
Jun 17, 2026
Apr 9, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party w...Show more
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software.Show less
1Zoom
1Zoom
Jun 17, 2026
Mar 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user shares a specific ap...Show more
Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user shares a specific application window via the Share Screen functionality, other meeting participants can briefly see contents of other application windows that were explicitly not shared. The contents of these other windows can (for instance) be seen for a short period of time when they overlay the shared window and get into focus. (An attacker can, of course, use a separate screen-recorder application, unsupported by Zoom, to save all such contents for later replays and analysis.) Depending on the unintentionally shared data, this short exposure of screen contents may be a more or less severe security issue.Show less
1Zoom
1Sharing Service
Jun 17, 2026
Aug 14, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate t...Show more
A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.Show less
1Zoom
1Zoom
Jun 17, 2026
Jun 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting...Show more
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting which could be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to trigger this vulnerability. For the most severe effect, target user interaction is required.Show less
1Zoom
1Zoom
Jun 17, 2026
Jun 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentiall...Show more
An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to exploit this vulnerability.Show less
1Zoom
1It Installer
Jun 17, 2026
May 4, 2020
N/A· v4
8.1 HIGH· v3
8.5 HIGH· v2
The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an updated version of the client. Standard users are able to write to this direc...Show more
The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an updated version of the client. Standard users are able to write to this directory, and can write links to other directories on the machine. As the installer runs with SYSTEM privileges and follows these links, a user can cause the installer to delete files that otherwise cannot be deleted by the user.Show less
1Zoom
1Meetings
Jun 17, 2026
Apr 17, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code