External risk intelligence

Zoom Workplace Privilege Escalation via Inefficient Regex

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-62484

The vulnerability affects Zoom Workplace and SDK components specifically on mobile platforms (Android and iOS). While these applications utilize network connectivity, they are client-side software rather than internet-facing infrastructure, services, or gateways, making public internet-exposed attack surface uncommon in typical deployments.

Zoom Meeting Software Development Kit

before 6.5.10

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Zoom Workplace and its Meeting Software Development Kit, potentially allowing unauthorized users to gain elevated privileges over the network. This issue stems from inefficient complexity in how the software handles certain text patterns. While this presents a significant technical risk, its direct impact on typical business operations requires further confirmation to understand the extent of exposure.

  • Code weakness allows privilege escalation.
  • Critical flaw impacts Zoom mobile applications.
  • Confirm relevance and any potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit a weakness in how Zoom clients handle complex text patterns. By sending specially crafted network traffic, an attacker could potentially gain elevated privileges on the affected client.

  • No authentication required.
  • Triggered via network access.
  • Potential for privilege escalation.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated user with network access to escalate privileges within the Zoom Workplace client. This could potentially impact the confidentiality, integrity, and availability of the application and its associated data when the affected client is in use.

  • User privilege escalation.
  • Network access to exploit complexity.
  • Compromise of application integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

Security and platform teams are responsible for addressing this vulnerability in Zoom Workplace clients and Meeting Software Development Kit components. The first step is to identify all instances of the affected software, assess their business criticality and network reachability, and confirm ownership for remediation planning.

  • Identify affected Zoom installations.
  • Confirm reachability and criticality of each.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Zoom Workplace and the Meeting SDK?

Zoom Workplace is a widely used application for video conferencing, team chat, and collaboration. The Meeting Software Development Kit (SDK) is a set of tools that allows developers to embed Zoom's video and audio capabilities directly into their own custom mobile applications. Both rely on shared underlying code to process network communications and manage user sessions on mobile devices like Android and iOS.

What does inefficient regular expression complexity mean for CVE-2025-62484?

This vulnerability is classified as CWE-1333, or Improper Handling of Inefficient Regular Expression Complexity. In plain English, the software uses a pattern-matching tool to process incoming text that can be tricked into working excessively hard. By sending a specifically crafted input, an attacker can cause the software to hang or process data in an unexpected way, which in this case allows them to bypass security controls and escalate their privileges.

How can an attacker trigger this vulnerability?

An attacker triggers this bug by sending malformed or complex network traffic directly to the Zoom Workplace or SDK application. It is important to note that simply being on the same network is not enough; the attacker must send specific, malicious data packets designed to exploit the regex flaw. Standard, legitimate network traffic and typical user interactions with the app do not trigger this weakness.

Do I need to worry if I use Zoom on a mobile device?

According to Halo Surface Signal, this vulnerability affects Zoom clients on Android and iOS mobile platforms. Because these are client-side applications rather than internet-facing servers or gateways, they generally lack the public-facing attack surface typically associated with high-risk infrastructure. However, you should evaluate if your mobile devices frequently connect to untrusted or public networks where such traffic could be intercepted.

When should I update my Zoom software to address this?

You should prioritize updating to version 6.5.10 or later immediately. The first step is to inventory all mobile devices within your organization that have Zoom Workplace or apps built with the Meeting SDK installed. Once identified, ensure these applications are updated through their respective app stores to resolve the regex processing flaw and eliminate the escalation path.

References