CVE-2025-67461 PUBLISHED

Zoom Rooms for macOS - External Control of File Name or Path

Assigner: Zoom
Reserved: 08.12.2025 Published: 10.12.2025 Updated: 10.12.2025

External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of information via local access.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CVSS Score: 5

Product Status

Vendor Zoom Communications Inc.
Product Zoom Rooms
Versions Default: unaffected
  • affected from 0 to 6.6.0 (excl.)

References

Problem Types

  • CWE-73: External Control of File Name or Path CWE