V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2025-27439
CVE
High

Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

CVSS
8.8
High
EPSS
0.00
p32
Published
2025-01-01
Updated
2025-01-01
Description

Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

Tags · CWE
CWE-124
Affected products
Meeting_software_development_kit < 6.3.0Rooms < 6.3.0Rooms_controller < 6.3.0Workplace < 6.3.0Workplace_desktop < 6.3.0Workplace_virtual_desktop_infrastructure < 6.1.16Workplace_virtual_desktop_infrastructure 6.1.17–6.2.12
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.004 · p32
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
meeting_software_development_kit*Tracked
rooms*Tracked
rooms_controller*Tracked
workplace*Tracked
workplace_desktop*Tracked
workplace_virtual_desktop_infrastructure*Tracked
Source databases
CVE
Related vulnerabilities