EXECUTIVE SUMMARY:
Zoom has addressing six vulnerabilities across its Workplace, Rooms, and SDK products for all major platforms including Windows, macOS, Linux. The issues include two buffer-overflow flaws in Windows clients, certificate-validation failure in Linux, improper authentication in macOS, a control‑flow weakness in iOS, and a cross‑site scripting (XSS) vulnerability affecting all platforms. These vulnerabilities could lead to denial of service, information disclosure, or compromise of data integrity.
CVE-2025-49464: This identifier covers two separate vulnerabilities—a buffer overflow in Zoom Workplace for Windows and improper authentication in macOS, both in versions prior to 6.4.5. These flaws may lead to denial of service or unauthorized access. This vulnerability is rated Medium severity with cvss 6.5.
RECOMMENDATION:
We strongly recommend you update Zoom Workplace to version 6.4.5 on Windows, macOS and to version 6.4.13 on Linux.
REFERENCES:
The following reports contain further technical details: