CVE-2025-46788

7.4

Zoom · Zoom Workplace for Linux

Zoom Workplace for Linux contains an improper certificate validation vulnerability that may permit unauthorized information disclosure via network access.

Executive summary

A critical improper certificate validation flaw in Zoom Workplace for Linux exposes users to potential information disclosure attacks via network-based interception.

Vulnerability

This vulnerability involves improper certificate validation (CWE-295) within the Zoom application. An unauthenticated attacker positioned on the network could exploit this weakness to intercept sensitive communications.

Business impact

Successful exploitation of this vulnerability can lead to the compromise of confidential data transmitted during Zoom sessions. Given the CVSS score of 7.4, this represents a high-severity risk that could result in unauthorized access to sensitive corporate communications, potentially leading to reputational damage or the loss of proprietary information.

Remediation

Immediate Action: Update Zoom Workplace for Linux to version 6.4.13 or later immediately to resolve the certificate validation issue.

Proactive Monitoring: Security teams should review network logs for unusual traffic patterns originating from or directed toward endpoints running Zoom Workplace for Linux.

Compensating Controls: Ensure that all network traffic is inspected via encrypted tunnels or VPNs to reduce the risk of interception by unauthorized parties on the local network segment.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Zoom Workplace for Linux must prioritize upgrading their installations to version 6.4.13. Due to the high potential for information disclosure during network-based attacks, failure to apply this update leaves the environment vulnerable to interception by unauthorized actors.

More Zoom CVEs

Sources