VulnerabilityAnalyzed
CVE-2025-58134
Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access.
MEDIUM 4.3EPSS 0.20%
Does this matter?
Lower severity and a low EPSS score (0.20%). Track it; it rarely justifies an emergency change on its own.
Description
Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.20% probability · 10th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- zoom/meeting software development kit · zoom/rooms · zoom/rooms controller · zoom/workplace desktop · zoom/workplace virtual desktop infrastructure
- Source
- security@zoom.us
References
- https://www.zoom.com/en/trust/security-bulletin/ZSB-25035Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.