📦 Meeting Software Development Kit

by Zoom

🔍 What is Meeting Software Development Kit?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-49457

CRITICAL CVSS 9.6 Aug 12, 2025

This vulnerability allows an unauthenticated attacker on the same network to escalate privileges on Windows systems running vulnerable Zoom clients. Attackers can exploit an untrusted search path issu...

CVE-2024-24691

CRITICAL CVSS 9.6 Feb 14, 2024

This vulnerability allows an unauthenticated attacker on the same network to escalate privileges on Windows systems running affected Zoom software. It affects Zoom Desktop Client for Windows, Zoom VDI...

CVE-2025-62484

HIGH CVSS 8.1 Nov 13, 2025

A regular expression complexity vulnerability in Zoom Workplace Clients allows unauthenticated attackers to potentially escalate privileges via network access. This affects Zoom Workplace Clients befo...

CVE-2025-64741

HIGH CVSS 8.1 Nov 13, 2025

An improper authorization vulnerability in Zoom Workplace for Android allows unauthenticated attackers with network access to escalate privileges. This affects all Android users running Zoom Workplace...

CVE-2025-30663

HIGH CVSS 8.8 May 14, 2025

A time-of-check time-of-use race condition vulnerability in Zoom Workplace Apps allows authenticated local users to escalate privileges. This affects users running vulnerable versions of Zoom Workplac...

CVE-2025-0150

HIGH CVSS 7.1 Mar 11, 2025

An incorrect behavior order vulnerability in Zoom Workplace Apps for iOS allows authenticated users to cause denial of service via network access. This affects Zoom Workplace Apps for iOS users runnin...

CVE-2025-0151

HIGH CVSS 8.5 Mar 11, 2025

This CVE describes a use-after-free vulnerability in Zoom Workplace Apps that allows authenticated users to escalate privileges through network access. The vulnerability affects users of Zoom Workplac...

CVE-2024-45421

HIGH CVSS 8.5 Feb 25, 2025

A buffer overflow vulnerability in some Zoom Apps allows authenticated users to escalate privileges through network access. This affects Zoom Apps users who have network connectivity to vulnerable sys...

CVE-2025-0147

HIGH CVSS 8.8 Jan 30, 2025

A type confusion vulnerability in Zoom Workplace App for Linux allows authenticated users to escalate privileges through network access. This affects Linux users running vulnerable versions of the Zoo...

CVE-2024-45419

HIGH CVSS 8.1 Nov 19, 2024

An improper input validation vulnerability in certain Zoom Apps allows unauthenticated attackers to access sensitive information via network access. This affects Zoom Apps that haven't been updated to...

CVE-2024-24697

HIGH CVSS 7.2 Feb 14, 2024

This vulnerability allows an authenticated user on a Windows system to escalate privileges by exploiting an untrusted search path in Zoom's 32-bit client. Attackers could gain higher system permission...

CVE-2023-49647

HIGH CVSS 8.8 Jan 12, 2024

This vulnerability allows authenticated users on Windows systems to escalate their privileges through local access to the Zoom Desktop Client, Zoom VDI Client, or Zoom SDKs. Attackers could gain highe...

CVE-2023-43585

HIGH CVSS 7.1 Dec 13, 2023

This vulnerability in Zoom Mobile App for iOS and Zoom SDKs for iOS allows authenticated users to access information they shouldn't have permission to view via network connections. It affects users ru...

CVE-2023-39215

HIGH CVSS 7.1 Sep 12, 2023

This vulnerability in Zoom clients allows authenticated users to cause denial of service attacks through network access. It affects Zoom users who have authentication credentials and could disrupt mee...

CVE-2023-36533

HIGH CVSS 7.1 Aug 8, 2023

This vulnerability in Zoom SDKs allows unauthenticated attackers to cause denial of service by consuming excessive resources through network access. It affects applications using vulnerable Zoom SDK v...

CVE-2025-64738

MEDIUM CVSS 5.0 Nov 13, 2025

This vulnerability in Zoom Workplace for macOS allows an authenticated user with local access to control file names or paths, potentially leading to information disclosure. It affects macOS users runn...

CVE-2025-64739

MEDIUM CVSS 4.3 Nov 13, 2025

This vulnerability in Zoom Clients allows unauthenticated attackers to control file paths, potentially leading to information disclosure via network access. It affects Zoom users running vulnerable cl...

CVE-2025-30669

MEDIUM CVSS 4.8 Nov 13, 2025

This vulnerability in Zoom Clients involves improper certificate validation that could allow an unauthenticated attacker on the same network to potentially access sensitive information. It affects Zoo...

CVE-2025-62482

MEDIUM CVSS 4.3 Nov 13, 2025

A cross-site scripting vulnerability in Zoom Workplace for Windows allows unauthenticated attackers to inject malicious scripts via network access. This could enable session hijacking, data theft, or ...

CVE-2025-62483

MEDIUM CVSS 5.3 Nov 13, 2025

This vulnerability in Zoom Clients allows unauthenticated attackers to access sensitive information through network access due to improper data removal. It affects Zoom Client users running versions b...

CVE-2025-58132

MEDIUM CVSS 4.1 Oct 15, 2025

This CVE describes a command injection vulnerability in Zoom Clients for Windows that allows authenticated users to execute arbitrary commands, potentially leading to information disclosure. The vulne...

CVE-2025-58135

MEDIUM CVSS 5.3 Sep 9, 2025

This vulnerability in Zoom Workplace Clients for Windows allows unauthenticated attackers to access sensitive information through network connections. It affects Windows users running vulnerable versi...

CVE-2025-49461

MEDIUM CVSS 4.3 Sep 9, 2025

A cross-site scripting vulnerability in certain Zoom Workplace Clients allows unauthenticated attackers to conduct denial of service attacks via network access. This affects users running vulnerable v...

CVE-2025-58134

MEDIUM CVSS 4.3 Sep 9, 2025

This CVE describes an incorrect authorization vulnerability in Zoom Workplace Clients for Windows that allows authenticated users to potentially modify data or settings via network access. The vulnera...

CVE-2025-49456

MEDIUM CVSS 6.2 Aug 12, 2025

A race condition vulnerability in Zoom Client for Windows installers could allow an unauthenticated local attacker to compromise application integrity during installation. This affects users installin...

CVE-2025-46785

MEDIUM CVSS 6.5 May 14, 2025

A buffer over-read vulnerability in Zoom Workplace Apps for Windows allows authenticated users to cause denial of service through network access. This affects Zoom Workplace users on Windows systems w...

CVE-2025-30665

MEDIUM CVSS 6.5 May 14, 2025

A NULL pointer dereference vulnerability in Zoom Workplace Apps for Windows allows authenticated users to cause a denial of service through network access. This affects Zoom Workplace users on Windows...

CVE-2025-30667

MEDIUM CVSS 6.5 May 14, 2025

A NULL pointer dereference vulnerability in Zoom Workplace Apps for Windows allows authenticated users to cause denial of service through network access. This affects Zoom Workplace users on Windows s...

CVE-2025-30670

MEDIUM CVSS 6.5 Apr 8, 2025

A null pointer dereference vulnerability in Zoom Workplace Apps for Windows allows authenticated users to cause denial of service through network access. This affects users running vulnerable versions...

CVE-2025-27442

MEDIUM CVSS 4.6 Apr 8, 2025

This cross-site scripting (XSS) vulnerability in Zoom Workplace Apps allows an unauthenticated attacker on the same network to inject malicious scripts into web pages. The vulnerability enables integr...

CVE-2025-0149

MEDIUM CVSS 6.5 Mar 11, 2025

This vulnerability in Zoom Workplace Apps allows unprivileged users to cause denial of service attacks by exploiting insufficient data authenticity verification. Attackers can disrupt Zoom services vi...

CVE-2024-27246

MEDIUM CVSS 4.3 Feb 25, 2025

A use-after-free vulnerability in Zoom Workplace Apps and SDKs allows authenticated users to cause denial of service through network access. This affects users of vulnerable Zoom applications who have...

CVE-2024-27239

MEDIUM CVSS 4.3 Feb 25, 2025

A use-after-free vulnerability in Zoom Workplace Apps and SDKs allows authenticated users to cause denial of service through network access. This affects users of vulnerable Zoom applications who have...

CVE-2024-45418

MEDIUM CVSS 5.4 Feb 25, 2025

This vulnerability in Zoom macOS installers allows authenticated users to escalate privileges via symlink attacks when network access is available. It affects macOS users running Zoom apps before vers...

CVE-2024-45424

MEDIUM CVSS 5.3 Feb 25, 2025

A business logic error in certain Zoom Workplace applications allows unauthenticated attackers to access sensitive information via network access. This affects organizations using vulnerable Zoom Work...

CVE-2024-45426

MEDIUM CVSS 4.9 Feb 25, 2025

This vulnerability in Zoom Workplace Apps allows privileged users to access information they shouldn't have permission to view through incorrect ownership assignment. It affects organizations using Zo...

CVE-2025-0143

MEDIUM CVSS 4.3 Jan 30, 2025

An out-of-bounds write vulnerability in Zoom Workplace App for Linux allows unauthorized attackers to cause denial of service via network access. This affects Linux users running Zoom Workplace App ve...

CVE-2025-0145

MEDIUM CVSS 4.6 Jan 30, 2025

This CVE describes a local privilege escalation vulnerability in Zoom Workplace Apps for Windows installers. An authorized user with local access can exploit an untrusted search path to gain elevated ...

CVE-2024-45422

MEDIUM CVSS 6.5 Nov 19, 2024

An improper input validation vulnerability in Zoom Apps before version 6.2.0 allows unauthenticated attackers to cause denial of service via network access. This affects Zoom Apps users running vulner...

CVE-2024-42437

MEDIUM CVSS 6.5 Aug 14, 2024

A buffer overflow vulnerability in Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers allows authenticated users to cause denial of service via network access. This affects organizations ...

CVE-2024-42439

MEDIUM CVSS 6.5 Aug 14, 2024

This CVE describes an untrusted search path vulnerability in Zoom Workplace Desktop App and Zoom Meeting SDK for macOS. It allows a privileged user with local access to escalate privileges on the syst...

CVE-2024-42441

MEDIUM CVSS 6.2 Aug 14, 2024

A privilege escalation vulnerability in Zoom's macOS installers allows local privileged users to gain higher system privileges. This affects Zoom Workplace Desktop App, Zoom Meeting SDK, and Zoom Room...

CVE-2024-42435

MEDIUM CVSS 4.9 Aug 14, 2024

This vulnerability allows privileged users within Zoom Workplace environments to access sensitive information through network connections. It affects Zoom Workplace Apps, SDKs, Rooms Clients, and Room...

CVE-2024-39823

MEDIUM CVSS 4.9 Aug 14, 2024

This CVE describes a missing authorization vulnerability in Zoom Workplace components that could allow privileged users to access sensitive information they shouldn't have permission to view. The vuln...

CVE-2024-39826

MEDIUM CVSS 6.8 Jul 15, 2024

A race condition vulnerability in Zoom Workplace Team Chat for Windows allows authenticated users to potentially access sensitive information through network access. This affects Zoom Workplace apps a...