CVE Vulnerabilities

CVE-2025-30669

Improper Certificate Validation

Published: Nov 13, 2025 | Modified: Jan 13, 2026
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Meeting_software_development_kitZoom*6.5.10 (excluding)
Workplace_desktopZoom*6.5.10 (excluding)
Workplace_virtual_desktop_infrastructureZoom*6.3.14 (excluding)
Workplace_virtual_desktop_infrastructureZoom6.4.10 (including)6.4.12 (excluding)

Potential Mitigations

References