logo

Windows Users at Risk as Critical Zoom Vulnerability Exploited

ID: 410d87e0-39ae-58e3-b8db-94b0e6980466

STIX ID: report--410d87e0-39ae-58e3-b8db-94b0e6980466

Feed Name: TechRepublic Security

Threat Score
85/100

Date Published: 2026-01-05

Date Updated: 2026-04-23

Author: Joseph Ofonagoro

...
...

A critical Windows-only DLL search-order vulnerability in Zoom (CVE-2025-49457, CVSS 9.6) has been reported as actively exploited; attackers can drop malicious DLLs that Windows may load in place of Zoom’s libraries, enabling privilege escalation, theft of recordings/credentials, and lateral movement. Zoom released a patch that fixes DLL loading by using absolute paths; users of Zoom Workspace for Windows, Zoom Workspace VDI for Windows, Zoom Meeting SDK for Windows, and Zoom Rooms/Controller on versions below 6.3.10 are urged to update immediately and keep auto-updates enabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.