Improper Certificate Validation in Zoom Workplace Desktop App for Linux and Zoom Meeting SDK for Linux - CVE-2025-46788
Published: July 8, 2025
Vulnerability identifier: #VU112509
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-46788
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper certificate validation. A remote attacker can perform MitM attack and compromise communication between the Zoom clients.
Affected software
Zoom Workplace Desktop App for Linux
Zoom Meeting SDK for Linux
Zoom Meeting SDK for Linux
How to mitigate CVE-2025-46788
Install updates from vendor's website.
Zoom Workplace Desktop App for Linux - update to 6.4.13 2309
Zoom Meeting SDK for Linux - update to 6.4.13
Zoom Meeting SDK for Linux - update to 6.4.13