CVE-2025-30662: Zoom Workplace Virtual Desktop Infrastructure

Medium severity, CVSS 6.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.

Affected products

  • Zoom Workplace Virtual Desktop Infrastructure: before 6.3.14 (fixed in 6.3.14); from 6.4.0, before 6.4.14 (fixed in 6.4.14); from 6.5.0, before 6.5.10 (fixed in 6.5.10)

Published 2025-11-13. Last modified 2026-10-07.