CVE-2025-49458

Description

Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.08

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-58135,CVE-2025-58134,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom Rooms (6.5.0.6131)Windows
Multiple vulnerabilities are fixed in Zoom Workplace (6.5.0.6118)Windows
Multiple vulnerabilities are fixed in Zoom Workplace (x64) (6.5.0.6118)Windows
Multiple vulnerabilities are fixed in Zoom Workplace (EXE) (User Based) (6.5.0.6118)Windows
Multiple vulnerabilities are fixed in Zoom Workplace (EXE) (x64) (User Based) (6.5.0.6118)Windows
Multiple vulnerabilities are fixed in Zoom Rooms (6.5.0.6131)Windows
Multiple vulnerabilities are fixed in Zoom Notes Plugin (6.5.0.1168)Windows
Multiple vulnerabilities are fixed in Zoom Outlook Plugin (6.5.0.1169)Windows
Vulnerabilities CVE-2025-58135,CVE-2025-58134,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom Workplace (6.4.12.64384)Windows
Vulnerabilities CVE-2025-58135,CVE-2025-58134,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom Workplace (EXE) (User Based) (6.4.12.64384)Windows
Vulnerabilities CVE-2025-58135,CVE-2025-58134,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom Workplace (EXE) (x64) (User Based) (6.4.12.64384)Windows
Vulnerabilities CVE-2025-58135,CVE-2025-58134,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom Workplace (x64) (6.4.12.64384)Windows
Vulnerabilities CVE-2025-58135,CVE-2025-58134,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom VDI Workplace (MSI) (x64) (6.4.12.26620)Windows
Vulnerabilities CVE-2025-58135,CVE-2025-58134,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom Workplace (6.5.0.6118)Windows
Vulnerabilities CVE-2025-58135,CVE-2025-58134,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom Workplace (x64) (6.5.0.6118)Windows
Vulnerabilities CVE-2025-58135,CVE-2025-58134,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom Workplace (EXE) (User Based) (6.5.0.6118)Windows
Vulnerabilities CVE-2025-58135,CVE-2025-58134,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom Workplace (EXE) (x64) (User Based) (6.5.0.6118)Windows
Vulnerabilities CVE-2025-58135,CVE-2025-58134,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom Notes Plugin (6.5.0.1168)Windows
Vulnerabilities CVE-2025-58135,CVE-2025-58134,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom Outlook Plugin (6.5.0.1169)Windows
Multiple vulnerabilities are fixed in Zoom Rooms 6.3.14Windows
Multiple vulnerabilities are fixed in Zoom Rooms 6.4.12Windows
Multiple vulnerabilities are fixed in Zoom Workplace (6.4.12.64384)Windows
Multiple vulnerabilities are fixed in Zoom Workplace (EXE) (User Based) (6.4.12.64384)Windows
Multiple vulnerabilities are fixed in Zoom Workplace (EXE) (x64) (User Based) (6.4.12.64384)Windows
Multiple vulnerabilities are fixed in Zoom Workplace (x64) (6.4.12.64384)Windows
Multiple vulnerabilities are fixed in Zoom VDI Workplace (MSI) (x64) (6.4.12.26620)Windows
Vulnerabilities CVE-2025-62483,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom for MAC 6.3.14Mac
Vulnerabilities CVE-2025-62483,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom for MAC (Intel) (6.4.12.56699)Mac
Vulnerabilities CVE-2025-62483,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom for MAC (Apple Silicon) (6.4.12.56699)Mac
Vulnerabilities CVE-2025-62483,CVE-2025-64739,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom for MAC 6.3.14Mac
Vulnerabilities CVE-2025-62483,CVE-2025-64739,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom for MAC (Intel) (6.4.12.56699)Mac
Vulnerabilities CVE-2025-62483,CVE-2025-64739,CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom for MAC (Apple Silicon) (6.4.12.56699)Mac
Vulnerabilities CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom for MAC (Intel) (6.5.0.57940)Mac
Vulnerabilities CVE-2025-49461,CVE-2025-49460,CVE-2025-49458 are fixed in Zoom for MAC (Apple Silicon) (6.5.0.57940)Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-350943Zoom Rooms (6.5.6.6405)
PATCH-351158Zoom Workplace (6.5.12.14128)
PATCH-351159Zoom Workplace (x64) (6.5.12.14128)
PATCH-351213Zoom Workplace (EXE) (User Based) (6.5.12.14128)
PATCH-351214Zoom Workplace (EXE) (x64) (User Based) (6.5.12.14128)
PATCH-350943Zoom Rooms (6.5.6.6405)
PATCH-349545Zoom Notes Plugin (6.5.0.1168)
PATCH-349727Zoom Outlook Plugin (6.5.5.1172)
PATCH-351158Zoom Workplace (6.5.12.14128)
PATCH-351213Zoom Workplace (EXE) (User Based) (6.5.12.14128)
PATCH-351214Zoom Workplace (EXE) (x64) (User Based) (6.5.12.14128)
PATCH-351159Zoom Workplace (x64) (6.5.12.14128)
PATCH-351377Zoom VDI Workplace (MSI) (x64) (6.5.10.26710)
PATCH-351158Zoom Workplace (6.5.12.14128)
PATCH-351159Zoom Workplace (x64) (6.5.12.14128)
PATCH-351213Zoom Workplace (EXE) (User Based) (6.5.12.14128)
PATCH-351214Zoom Workplace (EXE) (x64) (User Based) (6.5.12.14128)
PATCH-349545Zoom Notes Plugin (6.5.0.1168)
PATCH-349727Zoom Outlook Plugin (6.5.5.1172)
PATCH-612913Zoom IT for MAC (Intel) (6.6.11.70003)
PATCH-612912Zoom for MAC (Intel) (6.6.11.70003)
PATCH-612914Zoom for MAC (Apple Silicon) (6.6.11.70003)
PATCH-612913Zoom IT for MAC (Intel) (6.6.11.70003)
PATCH-612912Zoom for MAC (Intel) (6.6.11.70003)
PATCH-612914Zoom for MAC (Apple Silicon) (6.6.11.70003)
PATCH-612912Zoom for MAC (Intel) (6.6.11.70003)
PATCH-612914Zoom for MAC (Apple Silicon) (6.6.11.70003)
PATCH-353837Zoom Rooms (6.6.10.6938)
PATCH-353837Zoom Rooms (6.6.10.6938)
PATCH-353838Zoom Workplace (MSI) (6.6.11.23272)
PATCH-353839Zoom Workplace (User Based) (6.6.11.23272)
PATCH-353840Zoom Workplace (EXE) (x64) (User Based) (6.6.11.23272)
PATCH-353841Zoom Workplace (x64) (6.6.11.23272)
PATCH-353150Zoom VDI Workplace (MSI) (x64) (6.5.12.26790)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234