CVE-2025-30662

Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:macos:*:*

History

09 Jan 2026, 22:10

Type Values Removed Values Added
CPE cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:macos:*:*
References () https://www.zoom.com/en/trust/security-bulletin/zsb-25045 - () https://www.zoom.com/en/trust/security-bulletin/zsb-25045 - Vendor Advisory
First Time Zoom workplace Virtual Desktop Infrastructure
Zoom

13 Nov 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-13 15:15

Updated : 2026-01-09 22:10


NVD link : CVE-2025-30662

Mitre link : CVE-2025-30662

CVE.ORG link : CVE-2025-30662


JSON object : View

Products Affected

zoom

  • workplace_virtual_desktop_infrastructure
CWE
CWE-646

Reliance on File Name or Extension of Externally-Supplied File