Junglewise Threat Intelligence

CVE-2026-30900: Zoom Workplace for Windows privilege escalation in update functionality

CVE-2026-30900 · Severity: high · CVSS 7.8 · Published 2026-03-11

Technologies: Zoom Meeting SDK, Zoom Workplace VDI Client. Vendors: Zoom.

Executive brief

A vulnerability in the update mechanism of Zoom's Windows applications could allow a user with limited access to a computer to gain higher-level administrative privileges. Zoom is a widely used communication platform for video conferencing, chat, and collaboration. If exploited, an attacker who already has a basic account on a shared or compromised computer could take full control of the system, potentially accessing sensitive data or installing malicious software.

Technical details

A privilege escalation vulnerability exists in the update functionality of certain Zoom Clients for Windows due to an improper check of the minimum version (CWE-754). The flaw resides in how the updater validates software versions during the update process. A local, authenticated attacker with low privileges can exploit this logic error to execute code with elevated permissions. The vulnerability affects Zoom Workplace, VDI, and Meeting SDK versions within the 6.6.x branch. Users are advised to update to version 6.6.11 or later to remediate the issue.

Affected products

  • Zoom Workplace Desktop 6.6.0 to 6.6.10
  • Zoom Workplace VDI Client 6.6.10
  • Zoom Meeting SDK 6.6.0 to 6.6.10

Timeline

  • 2026-03-10: advisory: Initial publication of ZSB-26002 by Zoom
  • 2026-03-11: disclosed: CVE-2026-30900 published to NVD

References

Related threats