Zoom Rooms and Workplace Vulnerabilities Allow Attackers to Escalate Privileges
ID: ca7860c9-d01e-58f5-9794-ae496efc9071
STIX ID: report--ca7860c9-d01e-58f5-9794-ae496efc9071
Feed Name: cybersecurityNews.com
The report describes three newly disclosed Zoom vulnerabilities: two high-severity Windows flaws (CVE-2026-30906 in the Zoom Rooms installer via an untrusted search path, and CVE-2026-30905 in the Zoom Workplace VDI Plugin due to external control of a file name/path) that can allow a local authenticated user to escalate privileges, and a low-severity iOS issue (CVE-2026-30904) requiring physical access to bypass protections. Zoom has issued patches for all affected platforms and administrators are advised to apply updates immediately to mitigate potential privilege escalation risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
