CVE-2025-30662
⚪ Do wiadomości
Błąd w instalatorze Zoom Workplace VDI Plugin umożliwia ujawnienie informacji przez uwierzytelnionego użytkownika.
CVSS
6.6
EPSS
0.1%
Exploit
none
Vendor
zoom
Opis źródłowy (NVD)
Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.6 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2025-11-13 15:15:51 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 21:10:00 UTC |
Referencje
- https://www.zoom.com/en/trust/security-bulletin/zsb-25045 ([email protected]) [Vendor Advisory]