External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.
References
| Link | Resource |
|---|---|
| https://www.zoom.com/en/trust/security-bulletin/zsb-26007 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
03 Jun 2026, 01:26
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Zoom
Zoom workplace Virtual Desktop Infrastructure |
|
| CPE | cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:windows:*:* | |
| CWE | CWE-610 | |
| References | () https://www.zoom.com/en/trust/security-bulletin/zsb-26007 - Vendor Advisory |
13 May 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-13 19:17
Updated : 2026-06-03 01:26
NVD link : CVE-2026-30905
Mitre link : CVE-2026-30905
CVE.ORG link : CVE-2026-30905
JSON object : View
Products Affected
zoom
- workplace_virtual_desktop_infrastructure
