Path traversal in Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS - CVE-2025-64738
Published: November 11, 2025
Vulnerability identifier: #VU118244
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-64738
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can trick the victim into opening a specially crafted file and gain access to sensitive information.
Affected software
Zoom Workplace Desktop App for macOS
Zoom Meeting SDK for macOS
Zoom Meeting SDK for macOS
How to mitigate CVE-2025-64738
Install updates from vendor's website.
Zoom Workplace Desktop App for macOS - update to 6.5.10 62715
Zoom Meeting SDK for macOS - update to 6.5.10
Zoom Meeting SDK for macOS - update to 6.5.10