Zoom Workplace for Windows Vulnerability Allows Users to Escalate Privileges

A new security vulnerability has been discovered in Zoom Workplace VDI Client for Windows that could allow attackers to escalate their privileges on vulnerable systems.

The vulnerability affects users running outdated versions of the software and has been assigned a high severity rating.

Vulnerability Details

The flaw, identified as CVE-2025-64740, stems from improper verification of cryptographic signatures in the Zoom Workplace VDI Client installer for Windows.

An authenticated user with local access could exploit this weakness to gain elevated privileges on the system.

This means someone with basic user permissions could potentially take control of the entire computer.

Zoom assigned the vulnerability bulletin number ZSB-25042 and rated it with a CVSS score of 7.5, indicating a high-severity threat.

The attack requires local access and user interaction, but the potential impact is severe, affecting confidentiality, integrity, and availability of the affected system.

Unlike remote vulnerabilities that can be exploited over the internet, this flaw requires an attacker to already have access to the computer, either through physical presence or existing user credentials.

However, once an attacker with basic user access triggers the vulnerability, they can gain complete control of the system.

For organizations using Zoom Workplace VDI Client in virtual desktop infrastructure environments, this vulnerability poses a significant risk.

Virtual environments are often used in enterprises where sensitive work takes place, making privilege escalation particularly dangerous.

The vulnerability impacts Zoom Workplace VDI Client for Windows versions before:

  • Version 6.3.14
  • Version 6.4.12
  • Version 6.5.10

Users need to identify which version track they’re running to determine if they’re affected.

Zoom recommends that all users immediately update to the latest version available on the official download page at zoom.us/download.

Organizations should prioritize deploying patches to systems running vulnerable versions, particularly those handling sensitive information.

Users can check their Zoom version by opening Zoom and navigating to the Help menu to view their current version number.

Those using versions earlier than those listed above should update immediately.

Enterprises commonly use Zoom Workplace VDI Client to provide remote desktop access to their employees.

Regular updates are crucial to maintaining security in these environments, and this vulnerability should prompt immediate action across affected organizations.

FieldValue
CVE IDCVE-2025-64740
BulletinZSB-25042
ProductZoom Workplace VDI Client for Windows
Vulnerability TypeImproper Verification of Cryptographic Signature
Attack VectorLocal
CVSS Score7.5 (High)
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected Versions< 6.3.14, < 6.4.12, < 6.5.10
ImpactPrivilege Escalation

Find this Story Interesting! Follow us on Google NewsLinkedIn and X to Get More Instant Updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories