Vulnerability Intelligence Report
Zoom Workplace Clients - Inefficient Regular Expression Complexity
CVE-2025-62484
Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
No Active Exploit Signals
CVSS Base Score
8.1
HIGH
Exploitability:2.9
Impact Score:5.2
EPSS Probability:0.26%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-1333 ↗CWE-1333: Inefficient Regular Expression Complexity
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Zoom Communications Inc. | Zoom Workplace | 0 < 6.5.10 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.256%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Zoom Communications, Inc. · Vendor · USA |
| Reserved | 2025-10-14T23:02:23 |
| Published | 2025-11-13T15:07:57 |
| Patch Date | 2025-11-11 |
| Last Updated | 2026-02-26T16:57:04 |
Community Chatter & Buzz