Zoom and Xerox Release Urgent Security Updates to Address Privilege Escalation and RCE Vulnerabilities
Aug 13, 2025
Vulnerability / Software Security
Zoom and Xerox have released critical security updates for Zoom Clients on Windows and FreeFlow Core, addressing significant vulnerabilities that could enable privilege escalation and remote code execution (RCE). The flaw in Zoom Clients for Windows, designated as CVE-2025-49457 (CVSS score: 9.6), involves an untrusted search path that may allow an unauthenticated user to escalate privileges via network access.
According to a security bulletin issued by Zoom, the issue was identified by its Offensive Security team and affects the following products:
- Zoom Workplace for Windows versions prior to 6.3.10
- Zoom Workplace VDI for Windows versions prior to 6.3.10 (excluding 6.1.16 and 6.2.12)
- Zoom Rooms for Windows versions prior to 6.3.10
- Zoom Rooms Controller for Windows versions prior to 6.3.10
- Zoom Meeting SDK for Windows versions prior to 6.3.10
This disclosure follows the identification of multiple vulnerabilities in critical software platforms.
Vulnerability / Software Security
Zoom and Xerox Patch Serious Security Vulnerabilities On August 13, 2025, both Zoom and Xerox announced critical updates aimed at mitigating two significant security vulnerabilities found in their respective products. The flaws, affecting Zoom Clients for Windows and Xerox’s FreeFlow…