OS Command Injection in Zoom Video Communications, Inc. products - CVE-2025-30664

 

OS Command Injection in Zoom Video Communications, Inc. products - CVE-2025-30664

Published: May 13, 2025


Vulnerability identifier: #VU109003
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-30664
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Zoom Video Communications, Inc.
Affected software:
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux
Zoom Rooms Controller for Windows
Zoom Rooms Controller for macOS
Zoom Rooms Controller for Linux
Zoom Rooms Client for Windows
Zoom Rooms Client for macOS
Zoom Workplace App for iOS
Zoom Workplace App for Android
Zoom Rooms Controller for Android
Zoom Rooms Client for Android
Zoom Rooms Client for iPad
Zoom Meeting SDK for Windows
Zoom Meeting SDK for iOS
Zoom Meeting SDK for Android
Zoom Meeting SDK for macOS
Zoom Meeting SDK for Linux
Virtual Desktop Infrastructure (VDI)

Detailed vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper input validation. A local user can execute arbitrary OS commands on the target system with elevated privileges.


How to mitigate CVE-2025-30664

Install updates from vendor's website.

Sources