CVE-2025-0151 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. EPSS estimates a 0.40% chance of exploitation in the next 30 days.

## Description

Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

## Metrics

CVSS 3.1 8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability 0.40%

31.9th percentile

Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Weakness Enumeration

- [CWE-416](https://cwe.mitre.org/data/definitions/416.html)

## Affected Software

| Vendor | Product | Versions |
| --- | --- | --- |
| Zoom | Meeting Software Development Kit | < 6.3.0 |
| Zoom | Rooms | < 6.3.0 |
| Zoom | Rooms Controller | < 6.3.0 |
| Zoom | Workplace | < 6.3.0 |
| Zoom | Workplace Desktop | < 6.3.0 |
| Zoom | Workplace Virtual Desktop Infrastructure | < 6.1.16 |
| Zoom | Workplace Virtual Desktop Infrastructure | >= 6.1.17, < 6.2.12 |

## References

- [Vendor Advisory](https://www.zoom.com/en/trust/security-bulletin/zsb-25010/)

## Timeline

Published Mar 11, 2025

Last Modified Jun 17, 2026

Status Analyzed

## Frequently Asked Questions

**What is CVE-2025-0151?**

Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

**How severe is CVE-2025-0151?**

CVE-2025-0151 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.40% probability of exploitation in the next 30 days.

**How do I fix CVE-2025-0151?**

Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.

## Related CVEs from 2025

- [CVE-2025-0145](/content/cve/CVE-2025-0145/index.html)  Untrusted search path in the installer for some Zoom Workplace Apps - 7.8
- [CVE-2025-0146](/content/cve/CVE-2025-0146/index.html) Symlink following in the installer for Zoom Workplace App for - 5
- [CVE-2025-0147](/content/cve/CVE-2025-0147/index.html) Type confusion in the Zoom Workplace App for Linux before 6. - 9.8
- [CVE-2025-0148](/content/cve/CVE-2025-0148/index.html) Missing password field masking in the Zoom Jenkins Marketplace - 2.6
- [CVE-2025-0149](/content/cve/CVE-2025-0149/index.html) Insufficient verification of data authenticity in some Zoom - 7.5
- [CVE-2025-0150](/content/cve/CVE-2025-0150/index.html) Incorrect behavior order in some Zoom Workplace Apps for iOS - 6.5
- [CVE-2025-0152](/content/cve/CVE-2025-0152/index.html) IBM Engineering Requirements Management DOORS and DOORS Web - 6.1
- [CVE-2025-0154](/content/cve/CVE-2025-0154/index.html) IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose - 7.5
- [CVE-2025-0158](/content/cve/CVE-2025-0158/index.html) IBM EntireX 11.1 could allow a local user to cause a denial - 5.5
- [CVE-2025-0159](/content/cve/CVE-2025-0159/index.html) IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5 - 9.1
- [CVE-2025-0160](/content/cve/CVE-2025-0160/index.html) IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5 - 9.8
- [CVE-2025-0161](/content/cve/CVE-2025-0161/index.html) IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0 - 7.8
