← console
voxell vciy

CVE-2025-64741: Zoom Workplace for Android - Improper Authorization Handling

ROUTINE

Telemetry drift only. No threshold crossed and no authority ruling changed.

CVE record loaded 2026-09-20.

What to do now held facts and links

  1. Upgrade to 6.5.10 or later CVE record
  2. Record your decision, dated and frozen with today's evidence: patch by a date · mitigated by a compensating control · deferred · accepted the risk · not affected
  3. Check your version against the ranges this record publishes.

What it is stated by the CNA

Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.

weakness
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
affected
Zoom Communications Inc. Zoom Workplace for Android
versions
Zoom Communications Inc. Zoom Workplace for Android < 6.5.10
published ranges
zoom meeting software development kit < 6.5.10; zoom workplace < 6.5.10
fixed in
6.5.10
severity
8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
assigned by
Zoom
published
2025-11-13

check us zoom.com

Exploit code held, dated

exploit code
None held in the PoC-in-GitHub feed. A public repository changes this brief.

What moved held, dated

dateEPSSevent
14 Nov 20250.00058
19 Nov 20250.00063
21 Nov 20250.00084
15 Dec 20250.00121
14 Jan 20260.00096
20 Jan 20260.00111
15 Mar 20260.00146
9 Apr 20260.00058
12 Apr 20260.00076
23 Apr 20260.0009
9 Jun 20260.00101
15 Jun 20260.00407scoring model v2026.06.15
2 Jul 20260.00416
11 Jul 20260.00411
9 Aug 20260.00421

15 observations held. A step marked with a scoring model moved because the measurement was replaced, not because the vulnerability changed.

Outside the record researched, cited

This section reads the record's references and adds cited findings from outside it. It needs an account. Everything above is held facts and is complete without it.

Sign in to add the researched section

What would change this brief held, dated

CISA KEV
Not listed in the catalogue we hold. A listing changes this brief.
exploit probability
0.00 on 2026-08-09 (FIRST's EPSS, a probability and not evidence of exploitation). Next band line: 10% (0.10). Crossing a line changes this brief.
fix
Held: 6.5.10 (CVE record, loaded 2026-09-20). A newer fix from the CNA or OSV changes this brief.

Watch this CVE What counts as a move

How to check this

Every value above is held with two dates: when it was true upstream (as_of) and when we recorded it (tx_from). Re-derive the exploit probability as it stood on any date:

SELECT value, source, source_version, as_of, tx_from
FROM volatile_valid_as_of('CVE-2025-64741', '2026-10-03T23:59:59.999999Z', now());

Identity above is quoted from the CVE Program record, corpus cvelistv5_20260920, recorded 30 Sep 2026.