Junglewise Threat Intelligence

CVE-2026-30902: Zoom Clients for Windows privilege escalation

CVE-2026-30902 · Severity: high · CVSS 7.8 · Published 2026-03-11

Technologies: Zoom Workplace VDI Client for Windows, Zoom Workplace, Zoom Workplace VDI Client, Zoom Rooms. Vendors: Zoom.

Executive brief

A security vulnerability in Zoom's Windows applications could allow a user who already has basic access to a computer to gain higher-level system permissions. This could potentially allow an unauthorized individual to bypass security controls, access sensitive data, or modify system settings on the affected machine. The issue affects Zoom Workplace, Zoom Rooms, and Zoom VDI clients running on Windows.

Technical details

An improper privilege management vulnerability (CWE-269) exists in several Zoom clients for Windows, including Workplace, Rooms, and VDI versions. The flaw allows a locally authenticated user with low privileges to escalate their permissions on the host operating system. The vulnerability is triggered via local access and does not require user interaction. Successful exploitation grants the attacker high-level access (System/Admin), potentially leading to full compromise of the local machine's confidentiality, integrity, and availability. Zoom has released updates to address this in Workplace/Rooms version 6.6.0 and various VDI branch updates.

Affected products

  • Zoom Workplace for Windows before 6.6.0
  • Zoom Workplace VDI Client for Windows before 6.4.15, 6.5.13, and 6.6.10
  • Zoom Rooms for Windows before 6.6.0

Timeline

  • 2026-03-10: disclosed: Initial publication of security bulletin ZSB-26004
  • 2026-03-11: advisory: NVD publication date

References

Related threats