CVE-2025-30662

EUVD-2025-175306
Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.6 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
ZoomCNA
6.6 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
Affected Products (NVD)
VendorProductVersion
zoomworkplace_virtual_desktop_infrastructure
𝑥
< 6.3.14
zoomworkplace_virtual_desktop_infrastructure
6.4.0 ≤
𝑥
< 6.4.14
zoomworkplace_virtual_desktop_infrastructure
6.5.0 ≤
𝑥
< 6.5.10
𝑥
= Vulnerable software versions