logo

Zoom Rooms and Workplace Vulnerabilities Allow Attackers to Escalate Privileges

ID: ca7860c9-d01e-58f5-9794-ae496efc9071

STIX ID: report--ca7860c9-d01e-58f5-9794-ae496efc9071

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Abinaya

...
...

The report describes three newly disclosed Zoom vulnerabilities: two high-severity Windows flaws (CVE-2026-30906 in the Zoom Rooms installer via an untrusted search path, and CVE-2026-30905 in the Zoom Workplace VDI Plugin due to external control of a file name/path) that can allow a local authenticated user to escalate privileges, and a low-severity iOS issue (CVE-2026-30904) requiring physical access to bypass protections. Zoom has issued patches for all affected platforms and administrators are advised to apply updates immediately to mitigate potential privilege escalation risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.