Vulnerabilidades en Zoom Communications
15 resultadosAnálisis Vexday
A Zoom registra 11 vulnerabilidades conhecidas, com preocupante concentração recente: 10 foram publicadas nos últimos 90 dias, indicando fluxo contínuo de descobertas. A fraqueza dominante (CWE-20: Improper Input Validation) sugere deficiências sistemáticas em validação, embora apenas 2 atinjam nível crítico e nenhuma esteja sob exploração ativa confirmada no momento.
CVE-2026-53412CRITICALZoom Workplace VDI Plugin for Windows - Improper Input ValidationEPSS 0.6%CVE-2026-30903CRITICALExternal Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to coEPSS 0.3%CVE-2026-53407HIGHImproper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may alloEPSS 0.2%CVE-2026-53408HIGHImproper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may alloEPSS 0.2%CVE-2026-53409HIGHImproper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of priEPSS 0.2%CVE-2026-53411HIGHZoom Workplace VDI Plugin for Windows - Improper Input ValidationEPSS 0.1%CVE-2026-30904LOWProtection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of inforEPSS 0.1%CVE-2026-30906HIGHUntrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalatiEPSS 0.1%CVE-2026-30905HIGHExternal Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenEPSS 0.1%CVE-2026-53410HIGHZoom Clients for Windows - Race ConditionEPSS 0.1%CVE-2026-53406HIGHInsufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an autheEPSS 0.1%CVE-2026-53414MEDIUMZoom Clients - Buffer Over-readEPSS —CVE-2026-53415HIGHZoom Clients - Use After FreeEPSS —CVE-2026-53416HIGHZoom VDI - Path TraversalEPSS —CVE-2026-53413HIGHZoom Clients - Buffer Over-writeEPSS —