CVE-2025-30662

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/11/2025
Last modified:
09/01/2026

Description

Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:macos:*:* 6.3.14 (excluding)
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:macos:*:* 6.4.0 (including) 6.4.14 (excluding)
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:macos:*:* 6.5.0 (including) 6.5.10 (excluding)


References to Advisories, Solutions, and Tools