Rooms
Vendor:
First CVE: Sep 27, 2021 · Active for 4 years
107
Total CVEs
More Total CVEs than 99% of tracked products
17.8
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Rooms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 27, 2021
4 years ago
Most Recent CVE
May 13, 2026
73 days ago
CVE Severity & Scoring
Rooms107 CVEs
46%
52%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local44 (41.1%)
Network60 (56.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (2.8%)
Attack Complexity
Low100 (93.5%)
High7 (6.5%)
Unknown0 (0.0%)
User Interaction
None90 (84.1%)
Unknown0 (0.0%)
Required17 (15.9%)
Privileges Required
Low70 (65.4%)
High8 (7.5%)
None29 (27.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (107 CVEs).
107 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-49457HIGH Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access | Aug 12, 2025 | 8.8 | 33 | NO | NO |
CVE-2024-24691CRITICAL Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalati | Feb 14, 2024 | 9.8 | 32 | NO | NO |
CVE-2026-30906HIGH Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access. | May 13, 2026 | 7.8 | 30 | NO | NO |
CVE-2024-45421HIGH Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access. | Feb 25, 2025 | 8.8 | 28 | NO | NO |
CVE-2022-22786HIGH The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation versio | May 18, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-27440HIGH Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. | Mar 11, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-27439HIGH Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. | Mar 11, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-0151HIGH Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. | Mar 11, 2025 | 8.8 | 27 | NO | NO |
CVE-2024-39825HIGH Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access. | Aug 14, 2024 | 8.5 | 27 | NO | NO |
CVE-2026-30902HIGH Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access. | Mar 11, 2026 | 7.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (107 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (107 CVEs).
Media Mentions
Signals from CVEs in this product scope (107 CVEs).
Top CNAs Publishing CVEs For Rooms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.15.0 | 1 | 7.5 | 0.5% | 0 | 0 |