Zoom Workplace Apps Business Logic Error Allowing Unauthenticated Information Disclosure

Vulnerability

A business logic error has been identified in certain Zoom Workplace applications that may enable an unauthenticated user to disclose information through network access. This vulnerability affects several platforms, including desktop applications for Windows, macOS, and Linux, as well as mobile applications for iOS and Android. Additionally, it impacts the Zoom Meeting SDK across various operating systems and the Zoom Rooms App and Controller for multiple platforms.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure.

Remediation

Users are advised to update to the latest version of the Zoom Workplace App. The updated version can be downloaded from the Zoom Download Center.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
5.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.