logo

Zoom Rooms for Windows and macOS Flaws Enable Privilege Escalation and Sensitive Data Leaks

ID: 0b8611bd-0d80-5f52-9d77-c81676eca6e3

STIX ID: report--0b8611bd-0d80-5f52-9d77-c81676eca6e3

Feed Name: cybersecurityNews.com

Threat Score
50/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Zoom disclosed two vulnerabilities in Zoom Rooms for Windows and macOS prior to version 6.6.0: a Windows software downgrade protection bypass (ZSB-25050 / CVE-2025-67460) enabling local privilege escalation (CVSS 7.8) and a macOS file path/name control issue (ZSB-25051 / CVE-2025-67461) that can disclose sensitive information (CVSS 5.0). Both require local access, there is no evidence of active exploitation, and Zoom recommends updating to 6.6.0 or later while enterprises should audit deployments and enforce least-privilege controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.