
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30901 is an Improper Input Validation vulnerability in Zoom Rooms for Windows operating in Kiosk Mode that may allow an authenticated user to escalate privileges via local access. It affects all versions of Zoom Rooms for Windows before 6.6.5. The vulnerability was disclosed by Zoom on March 10, 2026, under security bulletin ZSB-26003. It carries a CVSS v3.1 base score of 7.8 (High) (Zoom Advisory).
The root cause is improper input validation (CWE-20) within the Kiosk Mode feature of Zoom Rooms for Windows. An authenticated local user can supply maliciously crafted input that bypasses expected validation controls, enabling privilege escalation on the affected system. The attack vector is local, requires low privileges, and no user interaction, making it exploitable by any authenticated user with physical or remote shell access to a Kiosk Mode device (Zoom Advisory, Zoom Security Bulletin).
Successful exploitation could allow an authenticated local attacker to gain elevated privileges on the affected Zoom Rooms for Windows device, resulting in unauthorized access to confidential information, unauthorized modification of system integrity, and potential denial of service. Because Kiosk Mode devices are often deployed in shared or semi-public environments (e.g., conference rooms), a low-privileged user gaining elevated access could facilitate further lateral movement within the corporate network (Zoom Advisory).
Zoom has released a patch in Zoom Rooms for Windows version 6.6.5, which resolves this vulnerability. Organizations should upgrade all affected Zoom Rooms for Windows installations to version 6.6.5 or later via https://zoom.us/download. As an additional control, restrict physical and remote access to Zoom Rooms Kiosk Mode devices to authorized personnel only, and implement strong access controls for Kiosk Mode environments (Zoom Advisory, Zoom Security Bulletin).
Security news outlets including CyberSecurityNews and SecurityOnline.info covered the vulnerability shortly after disclosure, noting it as part of a broader set of Zoom Workplace for Windows privilege escalation issues. Heise (English edition) also reported on the vulnerability, highlighting that Zoom's video conferencing software could allow attackers to escalate privileges. Community reaction was moderate, with no significant controversy or widespread alarm given the local-access-only attack vector and the absence of a public PoC (CyberSecurityNews, Heise).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."