CVE Vulnerabilities

CVE-2025-27439

Buffer Underwrite ('Buffer Underflow')

Published: Mar 11, 2025 | Modified: Oct 22, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

Weakness

The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.

Affected Software

NameVendorStart VersionEnd Version
Meeting_software_development_kitZoom*6.3.0 (excluding)
RoomsZoom*6.3.0 (excluding)
Rooms_controllerZoom*6.3.0 (excluding)
WorkplaceZoom*6.3.0 (excluding)
Workplace_desktopZoom*6.3.0 (excluding)
Workplace_virtual_desktop_infrastructureZoom*6.1.16 (excluding)
Workplace_virtual_desktop_infrastructureZoom6.1.17 (including)6.2.12 (excluding)

Potential Mitigations

References