Path traversal in Zoom Workplace Desktop App for Windows and Virtual Desktop Infrastructure (VDI) - CVE-2026-30903

 

Path traversal in Zoom Workplace Desktop App for Windows and Virtual Desktop Infrastructure (VDI) - CVE-2026-30903

Published: March 10, 2026


Vulnerability identifier: #VU123682
CSH Severity: High
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-30903
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to input validation error when processing files in the Mail feature. A remote attacker can trick the victim into opening a specially crafted email and overwrite arbitrary files on the system, leading to remote code execution. 


Affected software

Zoom Workplace Desktop App for Windows
Virtual Desktop Infrastructure (VDI)

How to mitigate CVE-2026-30903

Install updates from vendor's website.

Zoom Workplace Desktop App for Windows - update to 6.6.0 15547
Virtual Desktop Infrastructure (VDI) - addressed in versions 6.4.17.26900, 6.5.15.26910, 6.6.10.26830

External References

Related Security Bulletins