CVE-2025-49459
7.8Zoom · Zoom Workplace for Windows on ARM
A missing authorization vulnerability in the Zoom Workplace for Windows on ARM installer allows local authenticated users to perform an escalation of privilege.
Executive summary
A high-severity local privilege escalation vulnerability in Zoom Workplace for Windows on ARM allows authenticated users to compromise system integrity.
Vulnerability
This flaw is classified as a missing authorization issue (CWE-862) occurring within the software installer. It enables an authenticated user with local access to the system to escalate their privileges.
Business impact
Successful exploitation of this vulnerability allows a local user to gain elevated permissions on an affected workstation, potentially leading to full system compromise. With a CVSS score of 7.8, this vulnerability poses a significant risk to organizational endpoint security, as it facilitates lateral movement or the installation of persistent malicious software by users who should otherwise have limited access.
Remediation
Immediate Action: Update Zoom Workplace for Windows on ARM to version 6.6.0 or later to resolve the authorization flaw.
Proactive Monitoring: Review system logs for unusual installer activity or unexpected privilege changes occurring during or after software maintenance windows.
Compensating Controls: Restrict local user permissions on shared or sensitive workstations using the principle of least privilege to prevent unauthorized execution of installer packages.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS severity rating, administrators must prioritize the deployment of the vendor-supplied update to all affected ARM-based Windows endpoints. Ensuring that the Zoom client is updated to version 6.6.0 is the only reliable method to eliminate the escalation of privilege path provided by the vulnerable installer.