Zoom Security Update – 10 December 2025

Zoom has released a security update to fix multiple vulnerabilities in Zoom Rooms for Windows and macOS.

The addressed vulnerabilities could allow the attacker to gain elevated privileges or obtain sensitive information on the affected systems.

The addressed vulnerabilities:

1. Zoom Rooms for Windows – Software Downgrade Protection Mechanism Failure (CVE-2025-67460):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privilege

2. Zoom Rooms for macOS – External Control of File Name or Path (CVE-2025- 67461):

  • CVSS: 5
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Consequences: Obtain Information

The affected products:

  • Zoom Rooms for Windows before version 6.6.0.
  • Zoom Rooms for macOS before version 6.6.0.
Vulnerabilities
  • CVE-2025-67460
  • CVE-2025-67461
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Zoom Security Advisory

References