Zoom Workplace VDI Plugin for Windows - External Control of File Name or Path

  • ZSB-26007
  • CVE-2026-30905
  • High
  • 7.8
  • CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privledge via local access.

 

Users can help keep themselves secure by applying the latest updates available at https://zoom.us/download.

  • Zoom Workplace VDI Plugin version 6.6.10

Reported by sim0nsecurity

Revision Date Description
1.0 05/12/2026

Initial publication.