Vulnerability Management, Patch/Configuration Management

Multiple Ivanti, Zoom vulnerabilities fixed

SecurityWeek reports that Ivanti and Zoom have issued fixes for several security issues impacting their respective products.

Updates released by Ivanti address a trio of vulnerabilities impacting Ivanti Endpoint Manager versions earlier than 2024 SU4, including the path traversal bug, tracked as CVE-2025-9713; the insecure deserialization defect, tracked as CVE-2025-11622; and the insecure default permissions bug, tracked as CVE-2025-10918. Immediate updates have been recommended to prevent potential remote code execution and privilege escalation intrusions.

On the other hand, Zoom patched nine flaws affecting its mobile and desktop clients, three of which are high-severity. Attacks leveraging such issues, tracked as CVE-2025-62484, CVE-2025-64741, and CVE-2025-64740, could trigger escalated privileges.

Moreover, most of the remaining medium-severity vulnerabilities could be harnessed to leak information, while the remaining cross-site scripting bug could be leveraged to impact application integrity. Neither Ivanti nor Zoom reported any active exploitation of the fixed security weaknesses.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds