CRITICAL🇵🇱 Wersja polska

CVE-2026-30903

CVSS 9.6v3.1pub. 2026-03-11upd. 2026-05-14

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-73 (External Control of File Name or Path) and CWE-610 allows an external attacker to influence the file name or path used by the Mail function of the application. No authentication or local account is required — the attack can be carried out remotely over the network. User interaction (UI:R) is required to trigger the vulnerability, meaning the victim must perform a certain action, such as opening a message or clicking an element in the interface. The vulnerability can lead to privilege escalation through file or path manipulation by the application.

Impact

An unauthorized attacker can escalate privileges on the victim's system, potentially gaining access to sensitive data, modifying it, or causing service unavailability (full impact on confidentiality, integrity, and availability).

Mitigation & patch

Zoom Workplace for Windows should be updated to version 6.6.0 or newer. Detailed information is available in the vendor's security bulletin: https://www.zoom.com/en/trust/security-bulletin/zsb-26005

Who is affected

Zoom Workplace Desktop for Windows in versions prior to 6.6.0, Zoom Workplace Virtual Desktop Infrastructure (VDI) — versions indicated in vendor references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Zoom Workplace Desktop

    APP
    Zoom
    < 6.6.0
  • Zoom Workplace Virtual Desktop Infrastructure

    APP
    Zoom
    6.4.0 – 6.4.17 (excl.)6.5.0 – 6.5.15 (excl.)6.6.0 – 6.6.10 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-53412CRITICAL9.8PL ✓same product

Przejęcie konta przez sieć — błąd walidacji w Zoom Client dla Windows

CVE-2025-49457CRITICAL9.6PL ✓same product

Untrusted search path w klientach Zoom dla Windows — privilege escalation przez sieć

CVE-2026-53411HIGH7.8PL ✓same product

Privilege escalation przez TOCTOU w Zoom Client dla Windows

CVE-2026-53410HIGH7.0PL ✓same product

TOCTOU race condition w Zoom Client dla Windows — privilege escalation

CVE-2026-30905HIGH7.8same product

External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before vers...