Out-of-bounds write in Zoom Video Communications, Inc. products - CVE-2025-0143
Published: March 17, 2025
Vulnerability identifier: #VU105769
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-0143
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Zoom Video Communications, Inc.
Affected software:
Zoom Workplace Desktop App for Linux
Zoom Meeting SDK for Linux
Zoom Video SDK for Linux
Zoom Workplace Desktop App for Linux
Zoom Meeting SDK for Linux
Zoom Video SDK for Linux
Detailed vulnerability description
The vulnerability allows a remote attacker to crash the application.
The vulnerability exists due to a boundary error when processing untrusted input. A remote attacker can trick the victim into performing certain actions within the application, trigger an out-of-bounds write and crash the application.
How to mitigate CVE-2025-0143
Install updates from vendor's website.