Products

Showing 15 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Zoom Communications vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Zoom VDI - Path Traversal

Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.

CWE-23Aug 11, 2026
CVSS7.1v3.1EPSS0.17%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Zoom Clients - Use After Free

Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.

CWE-416Aug 11, 2026
CVSS8.3v3.1EPSS0.388%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Zoom Clients - Buffer Over-read

Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.

CWE-126Aug 11, 2026
CVSS6.5v3.1EPSS0.276%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Zoom Clients - Buffer Over-write

Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.

CWE-787Aug 11, 2026
CVSS8.3v3.1EPSS0.409%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Zoom Workplace VDI Plugin for Windows - Improper Input Validation

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.

CWE-20Jul 16, 2026
CVSS9.8v3.1EPSS0.647%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Zoom Workplace VDI Plugin for Windows - Improper Input Validation

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

CWE-20Jul 16, 2026
CVSS7.8v3.1EPSS0.132%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Zoom Clients for Windows - Race Condition

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

CWE-367Jul 16, 2026
CVSS7.0v3.1EPSS0.094%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Zoom Rooms for Windows Improper Privilege Management Local Privilege Escalation

Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.

CWE-20Jul 16, 2026
CVSS7.8v3.1EPSS0.152%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Zoom Workplace Custom URL Scheme Improper Authorization Leading to Privilege Escalation

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

CWE-939Jun 12, 2026
CVSS8.1v3.1EPSS0.211%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Zoom Workplace Custom URL Scheme Improper Authorization

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

CWE-939Jun 12, 2026
CVSS8.1v3.1EPSS0.231%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Zoom Remote Control for Zoom Contact Center Insufficient Verification of Data Authenticity Privilege Escalation

Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

CWE-345Jun 12, 2026
CVSS7.8v3.1EPSS0.08%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Zoom Rooms for Windows Installer Untrusted Search Path Privilege Escalation

Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

CWE-426May 13, 2026
CVSS7.8v3.1EPSS0.118%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Zoom Workplace VDI Plugin Windows Universal Installer External Control of File Name or Path Privilege Escalation

External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.

CWE-610CWE-73May 13, 2026
CVSS7.8v3.1EPSS0.118%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Zoom Workplace for iOS Protection Mechanism Failure Information Disclosure via Physical Access

Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of information via physical access.

CWE-693May 13, 2026
CVSS1.8v3.1EPSS0.143%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Zoom Workplace for Windows Mail Feature External Control of File Name or Path Privilege Escalation

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.

CWE-610CWE-73Mar 11, 2026
CVSS9.6v3.1EPSS0.328%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX