Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.zoom.com/en/trust/security-bulletin/zsb-25038 |
|
History
Tue, 21 Oct 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zoom meeting Software Development Kit
Zoom rooms Zoom workplace Desktop Zoom workplace Virtual Desktop Infrastructure |
|
| CPEs | cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:windows:*:* |
|
| Vendors & Products |
Zoom meeting Software Development Kit
Zoom rooms Zoom workplace Desktop Zoom workplace Virtual Desktop Infrastructure |
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Zoom Zoom zoom |
|
| Vendors & Products |
Microsoft
Microsoft windows Zoom Zoom zoom |
Thu, 16 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access. | |
| Title | Zoom Clients for Windows - Command Injection | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zoom
Published: 2025-10-15T16:10:20.442Z
Updated: 2025-10-22T03:55:12.755Z
Reserved: 2025-08-25T21:15:02.862Z
Link: CVE-2025-58132
Updated: 2025-10-16T13:29:37.259Z
Status : Analyzed
Published: 2025-10-15T17:15:59.917
Modified: 2025-10-21T19:32:07.400
Link: CVE-2025-58132
No data.