CVE-2026-30901
Received
Received - Intake
Improper Input Validation in Zoom Rooms Windows Enables Privilege Escalation
Publication date: 2026-03-11
Last updated on: 2026-03-11
Assigner: Zoom Video Communications, Inc.
Description
Description
Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduct an escalation of privilege via local access.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zoom | zoom_rooms | to 6.6.5 (exc) |
| zoom | zoom_rooms | 6.6.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-20 | The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. |