CVE-2026-30903

critical
Published 2026-03-11 · Modified 2026-05-14
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
9.8

Description

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@zoom.us — https://www.zoom.com/en/trust/security-bulletin/zsb-26005

Application impact

VendorProductVersionsFixed
zoomworkplace_desktop{"endExcluding":"6.6.0"}6.6.0
zoomworkplace_virtual_desktop_infrastructure{"startIncluding":"6.4.0","endExcluding":"6.4.17"}6.4.17

References

CWEs

CWE-73 CWE-610

Verify integrity in audit chain (admin only). AS-IS.