Windows Users at Risk as Critical Zoom Vulnerability Exploited
ID: 410d87e0-39ae-58e3-b8db-94b0e6980466
STIX ID: report--410d87e0-39ae-58e3-b8db-94b0e6980466
Feed Name: TechRepublic Security
A critical Windows-only DLL search-order vulnerability in Zoom (CVE-2025-49457, CVSS 9.6) has been reported as actively exploited; attackers can drop malicious DLLs that Windows may load in place of Zoom’s libraries, enabling privilege escalation, theft of recordings/credentials, and lateral movement. Zoom released a patch that fixes DLL loading by using absolute paths; users of Zoom Workspace for Windows, Zoom Workspace VDI for Windows, Zoom Meeting SDK for Windows, and Zoom Rooms/Controller on versions below 6.3.10 are urged to update immediately and keep auto-updates enabled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
