Home
MEDIUM: 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:NDefault status
unaffected
see references
affected
Description
Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.
Problem types
CWE-646: Reliance on File Name or Extension of Externally-Supplied File
Product status
see references
References
www.zoom.com/en/trust/security-bulletin/zsb-25045