{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-30662","assignerOrgId":"99b9af0d-a833-4a5d-9e2f-8b1324f35351","state":"PUBLISHED","assignerShortName":"Zoom","dateReserved":"2025-03-24T22:35:25.475Z","datePublished":"2025-11-13T14:53:09.801Z","dateUpdated":"2026-02-26T16:57:05.216Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["MacOS"],"product":"Zoom Workplace VDI Plugin macOS Universal installer","vendor":"Zoom Communications Inc.","versions":[{"status":"affected","version":"see references"}]}],"datePublic":"2025-11-11T13:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.</p>"}],"value":"Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":6.6,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-646","description":"CWE-646: Reliance on File Name or Extension of Externally-Supplied File","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"99b9af0d-a833-4a5d-9e2f-8b1324f35351","shortName":"Zoom","dateUpdated":"2025-11-13T14:53:09.801Z"},"references":[{"url":"https://www.zoom.com/en/trust/security-bulletin/zsb-25045"}],"source":{"discovery":"UNKNOWN"},"title":"Zoom Workplace VDI Plugin macOS Universal Installer - Symlink Following","x_generator":{"engine":"Vulnogram 0.5.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2025-30662","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2025-11-14T04:55:38.145806Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-26T16:57:05.216Z"}}]}}