Zoom has released critical security updates to patch three distinct flaws affecting its Windows and iOS applications.
The most dangerous of these allows authenticated attackers to elevate system privileges, effectively turning a standard user account into a high-level administrative threat.
Two high-severity vulnerabilities target Windows environments, both carrying a CVSS base score of 7.8 out of 10.
Both vulnerabilities represent a direct path for internal or compromised accounts to move laterally across enterprise networks a tactic frequently used in ransomware and data theft campaigns.
While Windows environments bear the brunt of the critical escalation risk, mobile users are not entirely in the clear.
| CVE ID | Product | Vulnerability Type | Severity | CVSS Score |
|---|---|---|---|---|
| CVE-2026-30906 | Zoom Rooms for Windows | Untrusted Search Path | High | 7.8 |
| CVE-2026-30905 | Zoom Workplace VDI Plugin (Windows) | External Control of File Name/Path | High | 7.8 |
| CVE-2026-30904 | Zoom Workplace for iOS | Protection Mechanism Failure | Low | 1.8 |
Privilege escalation vulnerabilities are highly prized by threat actors looking to move laterally across enterprise networks.
To prevent localized attacks from snowballing into full-scale corporate breaches, organizations must prioritize their software update pipelines without delay.
Zoom strongly urges all users, IT administrators, and remote workers to apply the latest patches immediately by downloading updated versions directly from the official Zoom download center.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google
The post Zoom Rooms and Workplace Flaws Allow Privilege Escalation Attacks appeared first on Cyber Security News.
UK politicians have strongly criticized GTA 6 developer Rockstar for its firing of 34 workers…
May is quite a big month for LEGO fans. Not only are there a wide…
Christopher Nolan has defended his upcoming movie, The Odyssey, from complaints about historical accuracy, after…
If you’re looking for recently released games to play on Switch, both Metroid Prime 4:…
Marvel fans are still puzzling over the decision to wrap up the wildly successful Ultimate…
Pokémon fans, it's time to clear out some space on your bookshelf, as the shiny…
This website uses cookies.