---
id: CVE-2025-30662
title: >-
  Symlink following in the installer for the Zoom Workplace VDI Plugin macOS
  Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their
  respective tracks may allow an authenticated user to conduct a disclosure of
  information vi…
summary: >-
  Symlink following in the installer for the Zoom Workplace VDI Plugin macOS
  Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their
  respective tracks may allow an authenticated user to conduct a disclosure of
  information vi…
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-646
vendor: zoom
product: workplace_virtual_desktop_infrastructure
affected:
  - workplace_virtual_desktop_infrastructure < 6.3.14
  - 'workplace_virtual_desktop_infrastructure >= 6.4.0, < 6.4.14'
  - 'workplace_virtual_desktop_infrastructure >= 6.5.0, < 6.5.10'
patched:
  - workplace_virtual_desktop_infrastructure 6.5.10
published: '2025-11-13'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-30662'
references:
  - url: 'https://www.zoom.com/en/trust/security-bulletin/zsb-25045'
    label: security@zoom.us
tags:
  - nvd
epss: 0.00129
epssPercentile: 0.02166
ingestedAt: '2026-10-07T21:54:15.031Z'
---

## Overview

Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.

## Affected

- `workplace_virtual_desktop_infrastructure < 6.3.14`
- `workplace_virtual_desktop_infrastructure >= 6.4.0, < 6.4.14`
- `workplace_virtual_desktop_infrastructure >= 6.5.0, < 6.5.10`

## Remediation

Upgrade past the affected range:

- `workplace_virtual_desktop_infrastructure 6.5.10`
