CVE-2025-58131
Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon - Race Condition
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.6EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
09 Sep 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or before 6.2.15 and 6.3.12 in their respective tracks) may allow an authenticated user to conduct a disclosure of information via network access.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Affected products
Zoom Communications, Inc · Zoom Workplace VDI Plugin macOS Universal installer for VMware HorizonWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →