External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HZoom Workplace Virtual Desktop Infrastructure
APPZoom< 6.6.11
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2026-53412CRITICAL9.8PL ✓ten sam produkt
Przejęcie konta przez sieć — błąd walidacji w Zoom Client dla Windows
CVE-2026-30903CRITICAL9.6PL ✓ten sam produkt
Zoom Workplace dla Windows — privilege escalation przez kontrolę ścieżki pliku w funkcji Mail
CVE-2025-49457CRITICAL9.6PL ✓ten sam produkt
Untrusted search path w klientach Zoom dla Windows — privilege escalation przez sieć
CVE-2026-53411HIGH7.8PL ✓ten sam produkt
Privilege escalation przez TOCTOU w Zoom Client dla Windows
CVE-2026-53410HIGH7.0PL ✓ten sam produkt
TOCTOU race condition w Zoom Client dla Windows — privilege escalation