CVE-2025-30663

HIGH

Zoom Meeting Software Development Kit < 6.4.0 - TOCTOU Race Condition

Title source: rule
STIX 2.1

Description

Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.

Scores

CVSS v3 8.8
EPSS 0.0004
EPSS Percentile 13.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-367
Status published
Products (6)
zoom/meeting_software_development_kit < 6.4.0 (5 CPE variants)
zoom/rooms < 6.4.0 (4 CPE variants)
zoom/rooms_controller < 6.4.0 (4 CPE variants)
zoom/workplace < 6.4.0 (2 CPE variants)
zoom/workplace_desktop < 6.4.0 (3 CPE variants)
zoom/workplace_virtual_desktop_infrastructure < 6.1.17
Published May 14, 2025
Tracked Since Feb 18, 2026