Impact
The vulnerability is a path traversal flaw in the Zoom VDI client and its plugins that allows an authenticated local user to read files outside the intended directory boundaries. This flaw provides the attacker with unauthorized access to sensitive files stored on the host machine, potentially exposing confidential data. The weakness is identified as CWE‑23.
Affected Systems
The flaw affects all versions of the Zoom Communications Zoom VDI product. No specific version constraints are listed in the CNA data, so all published releases may be vulnerable until patched.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability, but the EPSS score of less than 1 % suggests a low probability that the flaw will be exploited in the near term. It is not listed in the CISA KEV catalog. The attack requires the user to be authenticated on the system, so it is a local privilege issue rather than a remote exploitation vector. Once accessed locally, the attacker can reclaim data from arbitrary files.
OpenCVE Enrichment