Executive brief
Zoom's VDI (Virtual Desktop Infrastructure) Client and associated plugins contain a path traversal vulnerability that allows an authenticated user with local access to read sensitive files on the system. An attacker with local access to a machine running Zoom VDI could potentially extract configuration files, cached data, or other confidential information without requiring administrative privileges.
Technical details
This is a path traversal vulnerability (CWE-22) in Zoom VDI Client and Plugins that allows an authenticated local attacker to access files outside intended directories. The vulnerability requires local access and authentication to exploit, making the attack vector local. An authenticated user can traverse directory structures using specially crafted input to read arbitrary files on the system, leading to information disclosure. Patches are available through Zoom's security updates and should be applied immediately to affected installations.
Affected products
- Zoom VDI Client
Timeline
- 2026-08-11: disclosed
- 2026-08-11: advisory: Zoom security bulletin ZSB-26017 published