PT-2025-3756 · Zoom · Zoom Workplace App For Linux

Nahamsec

·

Published

2025-01-14

·

Updated

2025-08-01

·

CVE-2025-0147

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zoom Workplace App for Linux versions prior to 6.2.10
Description The issue is related to type confusion in the application, which may allow an authorized user to conduct an escalation of privilege via network access. This could potentially lead to unauthorized access and control. There is evidence of this issue being exploited in real-world attacks, with logs showing successful exploitation, memory region mapping, shellcode injection, and root privileges being obtained.
Recommendations For Zoom Workplace App for Linux versions prior to 6.2.10, update to version 6.2.10 or later to resolve the issue. As a temporary workaround, consider restricting network access to minimize the risk of exploitation.

Fix

LPE

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2025-02657
CVE-2025-0147

Affected Products

Zoom Workplace App For Linux