9.8

CVE-2026-30903

Medienbericht
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZoomWorkplace Desktop SwPlatformwindows Version < 6.6.0
ZoomWorkplace Virtual Desktop Infrastructure SwPlatformwindows Version >= 6.4.0 < 6.4.17
ZoomWorkplace Virtual Desktop Infrastructure SwPlatformwindows Version >= 6.5.0 < 6.5.15
ZoomWorkplace Virtual Desktop Infrastructure SwPlatformwindows Version >= 6.6.0 < 6.6.10
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.243
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security@zoom.us 9.6 2.8 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE-610 Externally Controlled Reference to a Resource in Another Sphere

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

CWE-73 External Control of File Name or Path

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
12.03.2026 14:48
https://www.zoom.com/en/trust/security-bulletin/zsb-26005
Vendor Advisory