CVE-2025-27441: Meeting Software Development Kit XSS (CVSS 5.2)

CVE-2025-27441 is a medium-severity vulnerability rated 5.2/10 on the CVSS scale. Cross-site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

Cross-site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

Metrics

Weakness Enumeration

Affected Software

Vendor Product Versions
Zoom Meeting Software Development Kit < 6.3.0
Zoom Meeting Software Development Kit < 6.3.10
Zoom Rooms < 6.4.0
Zoom Rooms Controller < 6.4.0
Zoom Workplace < 6.3.10
Zoom Workplace Desktop < 6.3.10
Zoom Workplace Virtual Desktop Infrastructure < 6.1.16
Zoom Workplace Virtual Desktop Infrastructure >= 6.1.17, < 6.2.12

References

Timeline

Frequently Asked Questions

What is CVE-2025-27441?

Cross-site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

How severe is CVE-2025-27441?

CVE-2025-27441 has a CVSS score of 5.2/10 (MEDIUM severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.

How do I fix CVE-2025-27441?

Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.