🔥 この記事の詳細
2026-08-12 更新
C
月内に

Zoom製品の複数の脆弱性

脆弱性🌐 英語ソース
🖥️ 製品Zoom
📅 2026-08-12📰 hkcert
📌 一言でいうと
Zoom製品の複数の脆弱性が公開されました。リモートの攻撃者がこれらを悪用し、機密情報の漏洩、リモートコード実行、およびデータの操作を行う可能性があります。Zoom Meeting SDK、Zoom Rooms、Zoom Workplaceなどの製品が影響を受けます。
🔍該当判定
  • PCやスマホで『Zoom Workplace』アプリを利用しており、バージョンが 7.0.6 未満(または 7.1.5 未満)である
  • 社内会議室などで『Zoom Rooms』を導入しており、バージョンが 7.1.5 未満である
  • Windowsの仮想デスクトップ環境(VDI)でZoomを利用しており、VDI Clientが 7.0.11 未満(または 6.6.16 未満)である
  • 自社開発のアプリやシステムに『Zoom Meeting SDK』を組み込んで利用しており、バージョンが 7.1.5 未満である
上記いずれにも該当しない → 静観でOK
該当時の対応
ベンダーが提供する最新の修正バージョンへアップデートしてください。詳細な修正内容はZoomのセキュリティ速報を確認してください。
📧 メール案を見る (社員向け + 管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【注意喚起】Zoomアプリの更新のお願い

お疲れさまです。情報システム担当です。
Zoomのアプリに、セキュリティ上の弱点(脆弱性)が見つかりました。放置すると、外部から不正に操作されたり、情報が漏れたりする恐れがあります。

ご協力をお願いしたいこと:
1. お使いのZoomアプリを最新バージョンにアップデートしてください。
2. アップデート方法が不明な場合は、社内ポータルを確認するか、情シスまでご連絡ください。

対応期限: 今週中
Subject: [Action Required] Please Update Your Zoom Application

Hi everyone,

Security vulnerabilities have been identified in Zoom applications. If left unpatched, these could potentially allow unauthorized access or data leakage.

What we need you to do:
1. Please update your Zoom application to the latest version immediately.
2. If you are unsure how to update, please check the internal portal or contact the IT support team.

Deadline: By the end of this week
件名: 【共有】Zoom製品の複数脆弱性への対応について

お疲れさまです。Zoom製品の脆弱性に関する情報共有です。

■ 概要
Zoom製品において、リモートコード実行 (RCE)、機密情報の漏洩、およびデータ操作を可能にする複数の脆弱性が報告されました。リスクレベルは中程度とされています。

■ 影響範囲
- Zoom Meeting SDK (ver 7.1.5 未満)
- Zoom Rooms (ver 7.1.5 未満)
- Zoom Workplace (ver 7.1.5 および 7.0.6 未満)
- Zoom Workplace VDI Client for Windows (ver 7.0.11 および 6.6.16 未満)
- Zoom Workplace VDI plugin (ver 7.0.11 および 6.6.15 未満)

■ 対応手順
1. 各環境で利用しているZoom製品のバージョンを確認する。
2. ベンダーが提供する最新の修正パッチを適用し、最新バージョンへ更新する。

■ 参考情報
- https://www.zoom.com/en/trust/security-bulletin/zsb-26015/
- https://www.zoom.com/en/trust/security-bulletin/zsb-26016/
- https://www.zoom.com/en/trust/security-bulletin/zsb-26017/

対応優先度: 中
対応期限: 速やかに
Subject: [Security Advisory] Addressing Multiple Vulnerabilities in Zoom Products

Hi all,

This is a technical update regarding multiple vulnerabilities identified in Zoom products.

■ Overview
Several vulnerabilities have been discovered that could allow a remote attacker to achieve Remote Code Execution (RCE), sensitive information disclosure, and data manipulation. The risk level is rated as Medium.

■ Affected Scope
- Zoom Meeting SDK (before 7.1.5)
- Zoom Rooms (before 7.1.5)
- Zoom Workplace (before 7.1.5 and 7.0.6 in respective branches)
- Zoom Workplace VDI Client for Windows (before 7.0.11 and 6.6.16)
- Zoom Workplace VDI plugin (before 7.0.11 and 6.6.15)

■ Remediation Steps
1. Audit the current versions of Zoom products deployed across the organization.
2. Apply the latest security updates provided by the vendor to mitigate these risks.

■ Reference
- https://www.zoom.com/en/trust/security-bulletin/zsb-26015/
- https://www.zoom.com/en/trust/security-bulletin/zsb-26016/
- https://www.zoom.com/en/trust/security-bulletin/zsb-26017/

Priority: Medium
Deadline: As soon as possible