Cyber Posture

CVE-2025-0150

High

Published: 11 March 2025

Published
11 March 2025
Modified
01 August 2025
KEV Added
Patch
CVSS Score 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
EPSS Score 0.0015 35.7th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-0150 is a high-severity Incorrect Behavior Order (CWE-696) vulnerability in Zoom Meeting Software Development Kit. Its CVSS base score is 7.1 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Application or System Exploitation (T1499.004); ranked at the 35.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 SC-5 (Denial-of-service Protection) and SI-2 (Flaw Remediation).

Threat & Defense at a Glance

What attackers do: exploitation maps to Application or System Exploitation (T1499.004). What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly mitigates CVE-2025-0150 by requiring timely remediation through patching the vulnerable Zoom Workplace iOS app to version 6.3.0 or later.

prevent

Implements denial-of-service protections at network boundaries to counter the high availability impact from authenticated network-based exploitation.

prevent

Establishes access controls and usage restrictions for mobile devices running vulnerable iOS apps, limiting low-privilege authenticated users' ability to trigger the flaw via network access.

MITRE ATT&CK Enterprise TechniquesAI

T1499.004 Application or System Exploitation Impact
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
Why these techniques?

The vulnerability enables remote exploitation of the Zoom iOS app leading to denial-of-service via incorrect behavior order, directly mapping to application or system exploitation under endpoint DoS.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

NVD Description

Incorrect behavior order in some Zoom Workplace Apps for iOS before version 6.3.0 may allow an authenticated user to conduct a denial of service via network access.

Deeper analysisAI

CVE-2025-0150 involves incorrect behavior order, classified under CWE-696, affecting Zoom Workplace Apps for iOS in versions before 6.3.0. This flaw enables an authenticated user to trigger a denial-of-service condition through network access. The vulnerability carries a CVSS v3.1 base score of 7.1, reflecting network attack vector (AV:N), low attack complexity (AC:L), low privileges required (PR:L), no user interaction (UI:N), unchanged scope (S:U), low confidentiality impact (C:L), no integrity impact (I:N), and high availability impact (A:H).

An authenticated user with low privileges can exploit this vulnerability remotely over the network, requiring minimal complexity and no user interaction on the target. Exploitation leads primarily to a denial-of-service, severely disrupting availability, alongside limited confidentiality exposure but without affecting integrity.

The Zoom security bulletin ZSB-25009, available at https://www.zoom.com/en/trust/security-bulletin/zsb-25009/, addresses this issue, with the vulnerability resolved in Zoom Workplace Apps for iOS version 6.3.0 and later.

Details

CWE(s)

Affected Products

zoom
meeting software development kit
≤ 6.3.0
zoom
workplace
≤ 6.3.0

CVEs Like This One

CVE-2025-62484Same product: Zoom Meeting Software Development Kit
CVE-2025-0149Same product: Zoom Meeting Software Development Kit
CVE-2025-0151Same product: Zoom Meeting Software Development Kit
CVE-2025-27440Same product: Zoom Meeting Software Development Kit
CVE-2024-45424Same product: Zoom Meeting Software Development Kit
CVE-2025-27439Same product: Zoom Meeting Software Development Kit
CVE-2024-45421Same product: Zoom Meeting Software Development Kit
CVE-2025-0147Same product: Zoom Meeting Software Development Kit
CVE-2026-35627Shared CWE-696
CVE-2024-45418Same product: Zoom Meeting Software Development Kit

References