9.8
CVE-2025-62484
- EPSS 0.26%
- Veröffentlicht 13.11.2025 15:07:57
- Zuletzt bearbeitet 19.11.2025 17:24:03
- Quelle security@zoom.us
- CVE-Watchlists
- Unerledigt
Zoom Workplace Clients - Inefficient Regular Expression Complexity
Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zoom ≫ Meeting Software Development Kit SwPlatformandroid Version < 6.5.10
Zoom ≫ Meeting Software Development Kit SwPlatformiphone_os Version < 6.5.10
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.167 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| security@zoom.us | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
|
CWE-1333 Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
https://www.zoom.com/en/trust/security-bulletin/zsb-25048