Executive brief
Zoom Workplace for Windows, a popular business communication and collaboration platform, contains a critical security flaw in its Mail feature. An attacker could exploit this vulnerability to gain unauthorized elevated permissions on a user's computer. This could lead to full system compromise, unauthorized access to sensitive corporate data, or the ability to install malicious software.
Technical details
A vulnerability classified as External Control of File Name or Path (CWE-73/CWE-610) exists in the Mail component of Zoom Workplace for Windows. The flaw allows an unauthenticated remote attacker to manipulate file paths or names, leading to an escalation of privilege. While the attack vector is network-based, the CVSS vector indicates that some level of user interaction is required (UI:R) and that the vulnerability can impact components beyond the initial security scope (S:C). Attackers can leverage this to gain higher-level system permissions. The issue is resolved in Zoom Workplace for Windows version 6.6.0 and various VDI client patches (6.4.17, 6.5.15, and 6.6.10).
Affected products
- Zoom Workplace for Windows before 6.6.0
- Zoom Workplace VDI Client for Windows before 6.4.17, 6.5.15, and 6.6.10
Timeline
- 2026-03-10: advisory: Initial publication of Zoom security bulletin ZSB-26005
- 2026-03-11: disclosed: CVE-2026-30903 published