CVE-2025-0151: Meeting Software Development Kit Use After Free
CVE-2025-0151 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
Metrics
CVSS 3.1 8.8/10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Probability 0.40%
31.9th percentile
Probability of exploitation in the next 30 days. Learn more
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zoom | Meeting Software Development Kit | < 6.3.0 |
| Zoom | Rooms | < 6.3.0 |
| Zoom | Rooms Controller | < 6.3.0 |
| Zoom | Workplace | < 6.3.0 |
| Zoom | Workplace Desktop | < 6.3.0 |
| Zoom | Workplace Virtual Desktop Infrastructure | < 6.1.16 |
| Zoom | Workplace Virtual Desktop Infrastructure | >= 6.1.17, < 6.2.12 |
References
Timeline
Published Mar 11, 2025
Last Modified Jun 17, 2026
Status Analyzed
Frequently Asked Questions
What is CVE-2025-0151?
Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
How severe is CVE-2025-0151?
CVE-2025-0151 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.40% probability of exploitation in the next 30 days.
How do I fix CVE-2025-0151?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Related CVEs from 2025
- CVE-2025-0145 Untrusted search path in the installer for some Zoom Workplace Apps - 7.8
- CVE-2025-0146 Symlink following in the installer for Zoom Workplace App for - 5
- CVE-2025-0147 Type confusion in the Zoom Workplace App for Linux before 6. - 9.8
- CVE-2025-0148 Missing password field masking in the Zoom Jenkins Marketplace - 2.6
- CVE-2025-0149 Insufficient verification of data authenticity in some Zoom - 7.5
- CVE-2025-0150 Incorrect behavior order in some Zoom Workplace Apps for iOS - 6.5
- CVE-2025-0152 IBM Engineering Requirements Management DOORS and DOORS Web - 6.1
- CVE-2025-0154 IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose - 7.5
- CVE-2025-0158 IBM EntireX 11.1 could allow a local user to cause a denial - 5.5
- CVE-2025-0159 IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5 - 9.1
- CVE-2025-0160 IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5 - 9.8
- CVE-2025-0161 IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0 - 7.8