# CVE-2025-30662

## Summary

- **CVE ID:** CVE-2025-30662
- **Severity:** MEDIUM
- **CVSS Score:** 6.6 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N)
- **CWE:** CWE-646
- **Published:** Nov 13, 2025
- **Last Modified:** Mar 12, 2026

## Description

Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.

## Affected Products

- Zoom Communications Inc. — Zoom Workplace VDI Plugin macOS Universal installer (see references)

## References

- [CNA](https://www.zoom.com/en/trust/security-bulletin/zsb-25045)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 2.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._