CVE-2025-49459

7.8

Zoom · Zoom Workplace for Windows on ARM

A missing authorization vulnerability in the Zoom Workplace for Windows on ARM installer allows local authenticated users to perform an escalation of privilege.

Executive summary

A high-severity local privilege escalation vulnerability in Zoom Workplace for Windows on ARM allows authenticated users to compromise system integrity.

Vulnerability

This flaw is classified as a missing authorization issue (CWE-862) occurring within the software installer. It enables an authenticated user with local access to the system to escalate their privileges.

Business impact

Successful exploitation of this vulnerability allows a local user to gain elevated permissions on an affected workstation, potentially leading to full system compromise. With a CVSS score of 7.8, this vulnerability poses a significant risk to organizational endpoint security, as it facilitates lateral movement or the installation of persistent malicious software by users who should otherwise have limited access.

Remediation

Immediate Action: Update Zoom Workplace for Windows on ARM to version 6.6.0 or later to resolve the authorization flaw.

Proactive Monitoring: Review system logs for unusual installer activity or unexpected privilege changes occurring during or after software maintenance windows.

Compensating Controls: Restrict local user permissions on shared or sensitive workstations using the principle of least privilege to prevent unauthorized execution of installer packages.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS severity rating, administrators must prioritize the deployment of the vendor-supplied update to all affected ARM-based Windows endpoints. Ensuring that the Zoom client is updated to version 6.6.0 is the only reliable method to eliminate the escalation of privilege path provided by the vulnerable installer.

More Zoom CVEs

Sources