CVE-2025-64741 is a critical improper authorization vulnerability in Zoom Workplace for Android versions prior to 6.5.10, also affecting the Zoom Meeting SDK. This flaw allows an unauthenticated attacker to achieve escalation of privilege via network access. With a CVSS score of 9.8, it poses a severe risk, enabling full compromise of confidentiality, integrity, and availability. While there are no known public exploits or active exploitation (KEV, Hot List inactive), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.5.10CPE matchmatch criteria | cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:android:*:* | ||
< 6.5.10CPE matchmatch criteria | cpe:2.3:a:zoom:workplace:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.