Zoom Security Update – 09 July 2025

Zoom has released a security update to fix multiple vulnerabilities in Zoom Client for Windows, macOS, and Linux.

The addressed vulnerabilities could allow the remote attacker to perform denial of service attacks or obtain sensitive information from the affected system.

Sample of the addressed vulnerabilities:

1. Zoom Workplace for Linux Improper Certificate Validation Vulnerability (CVE-2025-46788):

  • CVSS: 7.4
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information

2. Zoom Clients for Windows Buffer Overflow Vulnerability (CVE-2025-46789):

  • CVSS: 6.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Denial of Service
Vulnerabilities
  • CVE-2025-46788
  • CVE-2025-46789
  • CVE-2025-49462
  • CVE-2025-49463
  • CVE-2025-49464
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Zoom Security Advisory

References