ZeroHour

CVE-2026-30905

CVSS 3.1
7.8 high
EPSS
<1%p2
Published
()
Modified
Description

External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.

Vendors
zoom
Products
workplace virtual desktop infrastructure
Weakness
CWE-73, CWE-610
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.