Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Zoom Rooms for Windows and macOS Flaws Enable Privilege Escalation and Sensitive Data Leaks

Zoom Rooms for Windows and macOS Flaws Enable Privilege Escalation and Sensitive Data Leaks

Posted on December 9, 2025December 9, 2025 By CWS

Zoom has disclosed two essential safety vulnerabilities in its Zoom Rooms software program for Home windows and macOS, which might permit attackers with native entry to escalate privileges or expose delicate data.

Tracked as ZSB-25050 and ZSB-25051, these flaws have an effect on variations prior to six.6.0 and carry high-to-medium CVSS scores. Organizations counting on Zoom Rooms for convention setups face elevated dangers in shared environments like boardrooms or huddle areas.

The problems stem from a software program downgrade safety failure on Home windows and improper exterior management of file names on macOS, each of that are exploitable by way of native entry. Safety groups urge instant patching to stop unauthorized privilege positive factors or knowledge disclosures.

Home windows Software program Downgrade Safety Bypassed (ZSB-25050)

Zoom Rooms for Home windows earlier than model 6.6.0 suffers from a safety mechanism failure, enabling unauthenticated native customers to escalate privileges. This high-severity flaw, reported by an nameless researcher, might let attackers achieve elevated management over the system.

BulletinCVE IDCVSS SeverityCVSS ScoreVector StringDescriptionZSB-25050CVE-2025-67460High7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSoftware downgrade safety failure permits unauthenticated privilege escalation by way of native entry.

Affected Merchandise: Zoom Rooms for Home windows < 6.6.0

macOS File Path Management Vulnerability (ZSB-25051)

On macOS, an authenticated person can exploit exterior management of file names or paths to reveal delicate data. This medium-risk subject requires person interplay however might leak confidential knowledge in enterprise deployments.

BulletinCVE IDCVSS SeverityCVSS ScoreVector StringDescriptionZSB-25051CVE-2025-67461Medium5.0CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:NExternal management of file identify/path permits data disclosure by way of native entry.

Affected Merchandise: Zoom Rooms for macOS < 6.6.0

Zoom recommends updating to model 6.6.0 or later by way of the official obtain web page. No proof of energetic exploitation exists but, however the local-access vector fits insider threats or compromised endpoints.

These flaws spotlight ongoing dangers in collaboration instruments, particularly post-hybrid work shifts. Enterprises ought to audit Zoom Rooms deployments, implement least-privilege entry, and monitor for downgrade makes an attempt.

CISA has not but issued alerts, however vulnerability trackers like NVD will quickly listing these CVEs.

Comply with us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:Data, Enable, Escalation, Flaws, Leaks, macOS, Privilege, Rooms, Sensitive, Windows, Zoom

Post navigation

Previous Post: US Posts $10 Million Bounty for Iranian Hackers
Next Post: Google Announces 10 New AI Features for Google Chrome Powered by Gemini

Related Posts

CISA Alerts on N-able N-central Authentication Flaw CISA Alerts on N-able N-central Authentication Flaw Cyber Security News
U.S. Seizes Hundreds of Domains for Illegal World Cup Streaming U.S. Seizes Hundreds of Domains for Illegal World Cup Streaming Cyber Security News
Node.js Security Release Patches 7 Vulnerabilities Across All Release Lines Node.js Security Release Patches 7 Vulnerabilities Across All Release Lines Cyber Security News
TransparentTribe Attack Linux-Based Systems of Indian Military Organizations to Deliver DeskRAT TransparentTribe Attack Linux-Based Systems of Indian Military Organizations to Deliver DeskRAT Cyber Security News
PoC Exploits for CitrixBleed2 Flaw Released – Attackers Can Exfiltrate 127 Bytes Per Request PoC Exploits for CitrixBleed2 Flaw Released – Attackers Can Exfiltrate 127 Bytes Per Request Cyber Security News
GitLost Flaw Exposes GitHub Repos via AI Workflow GitLost Flaw Exposes GitHub Repos via AI Workflow Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SharePoint Exploit Emerges Following PoC Release
  • 737 VPN Extensions Expose Users to Proxy Risks
  • Fake CCleaner Download Spreads GhostDesk Spyware
  • Mindgard Secures $30M to Enhance AI Security
  • Flaw in AI APIs Allows Extraction of Hidden Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SharePoint Exploit Emerges Following PoC Release
  • 737 VPN Extensions Expose Users to Proxy Risks
  • Fake CCleaner Download Spreads GhostDesk Spyware
  • Mindgard Secures $30M to Enhance AI Security
  • Flaw in AI APIs Allows Extraction of Hidden Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark