
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30906 is an untrusted search path vulnerability (CWE-426) in the installer for Zoom Rooms for Windows that may allow an authenticated local user to escalate privileges. It affects all versions of Zoom Rooms for Windows before 7.0.0 and was disclosed by Zoom on May 12, 2026, with NVD publication on May 13, 2026. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Zoom Advisory, GitHub Advisory).
The vulnerability is classified as CWE-426 (Untrusted Search Path), meaning the Zoom Rooms installer searches for critical resources using a search path that can be manipulated by a local attacker. By placing a malicious executable or DLL in a directory that the installer searches before the legitimate resource location, an authenticated user with low privileges can cause the installer to load and execute attacker-controlled code. This technique maps to MITRE ATT&CK T1574.007 (Path Interception by PATH Environment Variable) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths). Exploitation requires only local access and low privileges, with no user interaction needed (Zoom Advisory, GitHub Advisory).
Successful exploitation grants an attacker high impact across confidentiality, integrity, and availability on the affected Windows system. Because the installer may run with elevated privileges, a low-privileged local user could escalate to SYSTEM or administrator-level access, enabling full control of the host, credential theft, persistence mechanisms, and potential lateral movement within the network (Zoom Advisory, GitHub Advisory).
%TEMP%, user profile directories, or directories in the user's PATH) with names matching Zoom Rooms installer dependencies; newly created files with timestamps coinciding with Zoom Rooms installer execution.msiexec.exe or ZoomRoomsInstaller.exe) with elevated privileges; unexpected processes running as SYSTEM originating from user-writable paths.Zoom has released version 7.0.0 of Zoom Rooms for Windows, which addresses this vulnerability. Organizations should update all Zoom Rooms for Windows installations to version 7.0.0 or later as the primary remediation. As a temporary workaround, restrict local user write access to directories included in the system PATH and ensure that only administrators can write to directories searched by the Zoom Rooms installer. Monitoring for unexpected file creation in installer search paths can help detect exploitation attempts (Zoom Advisory).
The vulnerability received coverage from several cybersecurity news outlets including CyberSecurityNews, GBHackers, CyberPress, and The Hacker News (in a weekly recap), indicating moderate community interest. Coverage generally focused on the broader set of Zoom Rooms and Zoom Workplace vulnerabilities disclosed in the same advisory cycle. No notable independent researcher commentary or significant social media debate has been identified beyond standard news reporting (CyberSecurityNews, The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."