CVE Vulnerabilities

CVE-2025-30662

Reliance on File Name or Extension of Externally-Supplied File

Published: Nov 13, 2025 | Modified: Jan 09, 2026
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.

Weakness

The product allows a file to be uploaded, but it relies on the file name or extension of the file to determine the appropriate behaviors. This could be used by attackers to cause the file to be misclassified and processed in a dangerous fashion.

Affected Software

NameVendorStart VersionEnd Version
Workplace_virtual_desktop_infrastructureZoom*6.3.14 (excluding)
Workplace_virtual_desktop_infrastructureZoom6.4.0 (including)6.4.14 (excluding)
Workplace_virtual_desktop_infrastructureZoom6.5.0 (including)6.5.10 (excluding)

Potential Mitigations

References