EXECUTIVE SUMMARY
Multiple security vulnerabilities have been identified in Zoom Workplace for Windows that could allow attackers to escalate privileges on affected systems. Notably, one critical vulnerability could be exploited remotely without requiring authentication. Systems running Zoom Workplace versions earlier than 6.6.0 are vulnerable and organizations are strongly advised to apply the latest security updates immediately to mitigate potential risks.
- CVE: CVE-2026-30903, CVE-2026-30902, CVE-2026-30901, CVE-2026-30900
- Active Region: Global
- Affected Sector: Organizations using Zoom for communication and collaboration.
- Affected Product: Zoom Workplace for Windows, Zoom Client for Windows, and Zoom Rooms for Win-dows.
- Severity: Critical (1 vulnerability) and High (3 vulnerabilities)
- Published Date: March 10, 2026
TECHNICAL DETAILS
- Target: Zoom Workplace for Windows, Zoom Client for Windows, and Zoom Rooms for Windows running versions prior to 6.6.0. The vulnerabilities primarily impact Windows endpoints in enterprise environments where Zoom is used for communication and collaboration.
- Root Cause: The vulnerabilities stem from improper privilege management, insufficient input validation, inadequate security checks, and external control of file names or paths. These weaknesses could allow attackers to manipulate application behavior, bypass security controls, and potentially escalate privileges on affected systems.
- Prerequisites for Exploitation: Exploitation requires the presence of a vulnerable Zoom client on a Windows system. The critical vulnerability may be exploitable……



