The vulnerabilities, detailed in Zoom Security Bulletin ZSB-25013, affect a wide range of Zoom Workplace applications, including desktop apps for Windows, macOS, and Linux and mobile apps for iOS and Android. Multiple null pointer dereference vulnerabilities (CVE-2025-30670, CVE-2025-30671, CVE-2025-30672) exist in Zoom Workplace Apps for Windows. Another vulnerability (CVE-2025-27443) affects Zoom Workplace Apps for Windows and is related to insecure default variable initialization. Zoom has released updates to address multiple vulnerabilities affecting its Workplace applications across various platforms. The vulnerability exists in some Zoom Workplace Apps. Zoom has released updated versions of the affected applications to address these vulnerabilities. The most severe vulnerability is a cross-site scripting (XSS) flaw (CVE-2025-27441, CVE-2025-27442) that carries a CVSS score of 4.6, classifying it as a medium severity issue. Zoom Engineering Security and fre3dm4n reported these vulnerabilities to Zoom. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 08 Apr 2025 15:15:11 +0000