Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Zoom Rooms for Windows and macOS Flaws Enable Privilege Escalation and Sensitive Data Leaks

Zoom has identified two critical security vulnerabilities in its Zoom Rooms software for Windows and macOS. These vulnerabilities, tracked as ZSB-25050 and ZSB-25051, could be exploited by attackers with local access to escalate privileges or expose…

Zoom has identified two critical security vulnerabilities in its Zoom Rooms software for Windows and macOS. These vulnerabilities, tracked as ZSB-25050 and ZSB-25051, could be exploited by attackers with local access to escalate privileges or expose sensitive information. The vulnerabilities affect versions prior to 6.6.0 and have been assigned high-to-medium CVSS scores.

Windows Software Downgrade Protection Bypassed (ZSB-25050)

The vulnerability in Zoom Rooms for Windows, identified as ZSB-25050, involves a failure in the software's downgrade protection mechanism. This flaw allows unauthenticated local users to escalate privileges, posing a high-severity risk. It was reported by an anonymous researcher.

Bulletin: ZSB-25050 CVE ID: CVE-2025-67460 CVSS Severity: High CVSS Score: 7.8 Vector String: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Description: Software downgrade protection failure allows unauthenticated privilege escalation via local access.

Affected Products: Zoom Rooms for Windows < 6.6.0

Zoom has identified two critical security vulnerabilities in its Zoom Rooms software for Windows and macOS.
Lucas Gallagher · Thehackingpost

macOS File Path Control Vulnerability (ZSB-25051)

The macOS vulnerability, identified as ZSB-25051, involves the external control of file names or paths, potentially leading to the disclosure of sensitive information. This medium-risk issue requires user interaction.

Bulletin: ZSB-25051 CVE ID: CVE-2025-67461 CVSS Severity: Medium CVSS Score: 5.0 Vector String: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N Description: External control of file name/path allows info disclosure via local access.

Affected Products: Zoom Rooms for macOS < 6.6.0

Advertisement

Zoom recommends updating to version 6.6.0 or later to address these vulnerabilities. Updates are available on the official download page . Although there is currently no evidence of active exploitation, the local-access vector presents risks, particularly from insider threats or compromised endpoints.

These vulnerabilities underscore the importance of regularly auditing collaboration tools, enforcing least-privilege access, and monitoring for potential downgrade attempts. CISA has not yet issued alerts regarding these vulnerabilities, but they are expected to be listed in vulnerability trackers like NVD soon.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories