ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-53409
Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local acc

Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.

NVD description · AI analysis pending
7.8<1%
  • zoom rooms
CVE-2026-53410
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authent

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

NVD description · AI analysis pending
7.0<1%
  • zoom remote control for zoom contact center
  • zoom rooms
  • zoom workplace desktop
  • +1 more
CVE-2026-53411
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authent

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

NVD description · AI analysis pending
7.0<1%
  • zoom workplace virtual desktop infrastructure
CVE-2026-53412
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.

NVD description · AI analysis pending
9.8<1%
  • zoom workplace desktop
  • zoom workplace virtual desktop infrastructure
Full article342 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 16, 2026Vulnerability / Enterprise Security

Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover.

The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Workplace for Windows before version 7.0.0 and Zoom Workplace VDI Client for Windows before version 7.0.10, 6.6.15, and 6.5.18 in their respective branches.

"Improper Input Validation in Zoom Desktop Client for Windows and Zoom VDI Client for Windows may allow an unauthenticated user to conduct an account takeover via network access," Zoom said in an advisory released this week.

The latest security fixes also address three high-severity flaws -

  • CVE-2026-53411 (CVSS score: 7.8) - An improper input validation vulnerability in the Zoom Workplace VDI Plugin for Windows before version 6.6.14 that may allow an authenticated user to conduct an escalation of privilege via local access.
  • CVE-2026-53410 (CVSS score: 7.0) - A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the installation and uninstallation process of certain Zoom Clients for Windows that could allow an authenticated local user to escalate privileges.
  • CVE-2026-53409 (CVSS score: 7.8) - An improper privilege management vulnerability in Zoom Rooms for Windows before version 7.1.0 that may allow an authenticated user to conduct an escalation of privilege via local access.

It's worth noting that CVE-2026-53410 affects the following products -

  • Zoom Workplace for Windows before version 7.0.5
  • Zoom Workplace VDI Client for Windows before 6.5.17 and 6.6.14 in their respective branch
  • Zoom Workplace VDI plugin for Windows before 6.5.17 and 6.6.14 in their respective branch
  • Zoom Rooms for Windows before 7.0.5
  • Remote Control for Zoom Contact Center for Windows before version 7.0.0

As of writing, there are no indications that any of the flaws are being exploited in real-world attacks. Users can stay protected by applying the latest updates.

(The story was updated after publication to reflect Zoom's removal of Meeting SDK for Windows as an affected product.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/07/zoom-patches-critical-windows-flaw-that.html