CVE-2025-30662CWE-646

Zoom Workplace VDI Plugin macOS Universal Installer - Symlink Following

Medium · published November 13, 2025

CVSS v3.1
6.6
EPSS
0%
Percentile
2.8
In the wild
Unconfirmed
What it is

Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.

The record
Technical detail
CVSS v3.1
6.6 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00129 · 2.8th percentile
Weakness
CWE-646 · Reliance on File Name or Extension of Externally-Supplied File
Published
2025-11-13T14:53Z
EPSS history
Timeline
  • 13 NOV 14:53Z
    Zoom Workplace VDI Plugin macOS Universal Installer - Symlink Following
    cvelistv5