CVE-2026-30906
Zoom Rooms vulnerability analysis and mitigation

Overview

CVE-2026-30906 is an untrusted search path vulnerability (CWE-426) in the installer for Zoom Rooms for Windows that may allow an authenticated local user to escalate privileges. It affects all versions of Zoom Rooms for Windows before 7.0.0 and was disclosed by Zoom on May 12, 2026, with NVD publication on May 13, 2026. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Zoom Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-426 (Untrusted Search Path), meaning the Zoom Rooms installer searches for critical resources using a search path that can be manipulated by a local attacker. By placing a malicious executable or DLL in a directory that the installer searches before the legitimate resource location, an authenticated user with low privileges can cause the installer to load and execute attacker-controlled code. This technique maps to MITRE ATT&CK T1574.007 (Path Interception by PATH Environment Variable) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths). Exploitation requires only local access and low privileges, with no user interaction needed (Zoom Advisory, GitHub Advisory).

Impact

Successful exploitation grants an attacker high impact across confidentiality, integrity, and availability on the affected Windows system. Because the installer may run with elevated privileges, a low-privileged local user could escalate to SYSTEM or administrator-level access, enabling full control of the host, credential theft, persistence mechanisms, and potential lateral movement within the network (Zoom Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a target Windows system running Zoom Rooms for Windows with a version prior to 7.0.0, requiring local authenticated access (e.g., via a shared workstation or conference room device).
  2. Identify installer search path: Analyze the Zoom Rooms installer to determine which directories are searched for executables or DLLs during installation or update, particularly any user-writable directories that appear early in the PATH or installer search order.
  3. Plant malicious binary: Place a crafted malicious DLL or executable with the expected name in a user-writable directory that precedes the legitimate resource location in the search path (e.g., a temp directory or a directory in the user's PATH).
  4. Trigger installer execution: Wait for or trigger the Zoom Rooms installer to run (e.g., during an update or reinstallation), causing it to load the attacker-controlled binary instead of the legitimate one.
  5. Achieve privilege escalation: The malicious binary executes in the context of the installer's elevated privileges, granting the attacker SYSTEM or administrator-level access on the host (Zoom Advisory, GitHub Advisory).

Indicators of compromise

  • File System: Unexpected DLL or executable files placed in user-writable directories (e.g., %TEMP%, user profile directories, or directories in the user's PATH) with names matching Zoom Rooms installer dependencies; newly created files with timestamps coinciding with Zoom Rooms installer execution.
  • Process: Unusual child processes spawned by the Zoom Rooms installer process (e.g., msiexec.exe or ZoomRoomsInstaller.exe) with elevated privileges; unexpected processes running as SYSTEM originating from user-writable paths.
  • Logs: Windows Event Logs (Security) showing privilege escalation events (Event ID 4672, 4688) associated with the Zoom Rooms installer; application logs recording DLL or binary loads from non-standard paths during Zoom Rooms installation.
  • Network: Outbound connections from newly spawned elevated processes to external IPs shortly after Zoom Rooms installer execution, potentially indicating post-exploitation activity.

Mitigation and workarounds

Zoom has released version 7.0.0 of Zoom Rooms for Windows, which addresses this vulnerability. Organizations should update all Zoom Rooms for Windows installations to version 7.0.0 or later as the primary remediation. As a temporary workaround, restrict local user write access to directories included in the system PATH and ensure that only administrators can write to directories searched by the Zoom Rooms installer. Monitoring for unexpected file creation in installer search paths can help detect exploitation attempts (Zoom Advisory).

Community reactions

The vulnerability received coverage from several cybersecurity news outlets including CyberSecurityNews, GBHackers, CyberPress, and The Hacker News (in a weekly recap), indicating moderate community interest. Coverage generally focused on the broader set of Zoom Rooms and Zoom Workplace vulnerabilities disclosed in the same advisory cycle. No notable independent researcher commentary or significant social media debate has been identified beyond standard news reporting (CyberSecurityNews, The Hacker News).

Additional resources


SourceThis report was generated using AI

Related Zoom Rooms vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-53409HIGH7.8
  • Zoom Rooms logoZoom Rooms
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesJul 16, 2026
CVE-2026-30906HIGH7.8
  • Zoom Rooms logoZoom Rooms
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesMay 13, 2026
CVE-2026-30902HIGH7.8
  • Zoom Rooms logoZoom Rooms
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesMar 11, 2026
CVE-2026-30901HIGH7.8
  • Zoom Rooms logoZoom Rooms
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesMar 11, 2026
CVE-2026-53410HIGH7
  • Zoom Rooms logoZoom Rooms
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesJul 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management