CVE-2025-62484 describes a critical vulnerability in certain Zoom Workplace Clients before version 6.5.10, stemming from inefficient regular expression complexity. This flaw allows an unauthenticated attacker to achieve escalation of privilege via network access, posing a significant risk to affected systems. With a CVSS score of 9.8 (CRITICAL), the vulnerability has a low attack complexity and high impact on confidentiality, integrity, and availability. While not currently in the KEV catalog or actively exploited, its high FAUCET Risk Score and mentions in community discussions and media coverage indicate its potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.5.10CPE matchmatch criteria | cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:android:*:* | ||
< 6.5.10CPE matchmatch criteria | cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:iphone_os:*:* | ||
< 6.5.10CPE matchmatch criteria | cpe:2.3:a:zoom:workplace:*:*:*:*:*:android:*:* | ||
< 6.5.10CPE matchmatch criteria | cpe:2.3:a:zoom:workplace:*:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.