CVE Vulnerabilities

CVE-2025-64740

Improper Verification of Cryptographic Signature

Published: Nov 13, 2025 | Modified: Jan 13, 2026
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
Workplace_virtual_desktop_infrastructureZoom*6.3.14 (excluding)
Workplace_virtual_desktop_infrastructureZoom6.4.10 (including)6.4.12 (excluding)

References