HomeUpdatesZoom fixes multiple serious vulnerabilities

Zoom fixes multiple serious vulnerabilities

Zoom has announced a series of security bulletinsthat patch significant vulnerabilities in its Zoom Workplace, noting that two of the vulnerabilities are rated “high severity.” The new issues affect millions of users who rely on the video conferencing platform for work and collaboration, highlighting the ongoing security challenges in the digital workplace.

Zoom vulnerabilities

The updates come at a time when cybersecurity experts are warning of an increase in attacks on collaboration tools, which, due to their widespread use, are an attractive target for hackers seeking access to corporate networks and data.

The most critical vulnerabilities: Android and Windows VDI under the microscope

Zoom has confirmed two serious security flaws: they come from ZSB-25043 and ZSB-25042.

See also: expr-eval: Critical vulnerability exposes AI and NLP apps to risk

The first, affecting Zoom Workplace for Android, is identified as CVE-2025-64741 and relates to an improper authorization management. This vulnerability could allow attackers to bypass access controls and join meetings or obtain sensitive data without permission.

The second, CVE-2025-64740, is found in the VDI Client for Windows and concerns insufficient cryptographic signature verification. This weakness could allow the introduction of tampered updates or even malicious software packages — a scenario reminiscent of supply chain attacks of recent years.

Researchers emphasize that such vulnerabilities can be used for large-scale breaches, as attackers pretend to be reliable sources of information.

Zoom fixes multiple serious vulnerabilities

Medium severity vulnerabilities and stability issues

In addition to the two main threats, Zoom is also facing medium severity path traversal issues . ZSB-25041 , which affects multiple Zoom Clients (CVE-2025-64739), could allow malicious actors to change the file storage path, leading to potential data leakage or arbitrary code execution .

See also: Elastic Defend for Windows: Vulnerability allows privilege escalation

Similarly, in Zoom Workplace for macOS (CVE-2025-64738), incorrect input processing could allow critical system files to be overwritten. Although these issues are rated “medium severity,” they are a clear reminder of the need for stronger input sanitization in cross-platform tools.

Added to the same list is ZSB-25015, which concerns null pointer dereferences in Windows applications. These bugs do not allow direct execution of malicious code, but they can cause downtime or temporary denial-of-service (DoS), affecting business continuity.

Reactions and next steps

Zoom urges all users to immediately update their applications to the latest versions for Android, Windows, macOS and VDI.

The Bigger Picture: Videoconferencing and Cybersecurity

These updates are not an isolated incident. Since August 2025, Zoom has released multiple security updates, addressing critical issues related to untrusted search paths, buffer overflows, and inadequate authentication. The increased frequency shows that video conferencing platforms have become a significant target for cyberattacks, as they collect sensitive corporate data and contact information.

See also: Amazon WorkSpaces for Linux: Vulnerability allows credential extraction

Given that remote work and hybrid models have become established, the security of collaborative applications is now a critical factor in operational resilience.

Zoom fixes multiple serious vulnerabilities

What should organizations do?

Experts recommend that businesses implement policies regular notification, enable multi-factor authentication (MFA) , and use anomaly detection software to monitor suspicious behavior in video conferencing applications. At the same time, training staff on cybersecurity issues and creating a clear incident response plan are essential steps to reduce risk.

Zoom’s new round of updates is a reminder that even the most established platforms are not immune to vulnerabilities. Organizations that rely on video conferencing tools should treat every patch as a line of defense against increasingly targeted attacks.
Security is no longer just a technical issue — it’s a foundation for digital collaboration.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS