Improper authentication in Zoom Video Communications, Inc. products - CVE-2025-58133

 

Improper authentication in Zoom Video Communications, Inc. products - CVE-2025-58133

Published: October 14, 2025


Vulnerability identifier: #VU116989
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-58133
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error when processing authentication requests. A remote attacker can bypass authentication process and gain access to sensitive information. 


Affected software

Zoom Rooms Client for macOS
Zoom Rooms Client for Windows
Zoom Rooms Client for iPad
Zoom Rooms Client for Android

How to mitigate CVE-2025-58133

Install updates from vendor's website.

Zoom Rooms Client for macOS - update to 6.5.1
Zoom Rooms Client for Windows - update to 6.5.1
Zoom Rooms Client for iPad - update to 6.5.1
Zoom Rooms Client for Android - update to 6.5.1

External References

Related Security Bulletins