Zoom Rooms and Workplace Flaws Expose Users to Elevated Access Attacks
ID: 97b13a54-35ce-5c7f-903c-6d788f45c19e
STIX ID: report--97b13a54-35ce-5c7f-903c-6d788f45c19e
Feed Name: GBHackers
The report discloses three Zoom vulnerabilities — two high-severity local privilege escalation bugs in Zoom Rooms for Windows (CVE-2026-30906, CVSS 7.8) and Zoom Workplace VDI Plugin for Windows (CVE-2026-30905, CVSS 7.8), plus a low-severity information disclosure on iOS (CVE-2026-30904, CVSS 1.8). Affected versions are Zoom Rooms for Windows <7.0.0, VDI Plugin 6.6.10 (update to ≥6.6.11), and iOS app <7.0.0; Zoom recommends immediate application of security updates to prevent local authenticated privilege escalation that could lead to disabling security controls, data theft, or ransomware deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
