Executive brief
Zoom Rooms for Windows, a software solution used to manage conference room hardware, contains a security flaw when running in Kiosk Mode. An individual with physical or local access to the computer can exploit this vulnerability to gain higher-level system permissions. This could allow an unauthorized user to bypass security restrictions, access sensitive data, or compromise the underlying operating system.
Technical details
A privilege escalation vulnerability exists in Zoom Rooms for Windows (versions prior to 6.6.5) specifically when the application is operating in Kiosk Mode. The flaw stems from improper input validation (CWE-20), which can be leveraged by a locally authenticated user. While the attack requires local access and faces high complexity (AC:H), a successful exploit allows the attacker to gain elevated permissions on the host Windows system. Zoom has addressed this issue in version 6.6.5.
Affected products
- Zoom Rooms before 6.6.5
Timeline
- 2026-03-10: advisory: Zoom security bulletin ZSB-26003 published
- 2026-03-11: disclosed: CVE-2026-30901 published to NVD