CVE-2025-62483Medium· 5.3▾ SunlitImproper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.
meeting_software_development_kit < 6.5.10rooms < 6.5.10rooms_controller < 6.5.10workplace_desktop < 6.5.10workplace_virtual_desktop_infrastructure < 6.3.14workplace_virtual_desktop_infrastructure >= 6.4.10, < 6.4.12Upgrade past the affected range:
meeting_software_development_kit 6.5.10rooms 6.5.10rooms_controller 6.5.10workplace_desktop 6.5.10workplace_virtual_desktop_infrastructure 6.4.12Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62482Medium· 4.3Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.
CVE-2025-62484High· 8.1Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
CVE-2025-30669Medium· 4.8Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.
CVE-2025-30662Medium· 6.6Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information vi…
CVE-2025-67461Medium· 5.0External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of information via local access.
CVE-2025-67460High· 7.8Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via local access.