Zoom has fixed a critical flaw in its Windows desktop and VDI apps that could let an attacker take over
user accounts over the network, with no password or user action needed. No attacks have been
reported, but the flaw scores 9.8 out of 10 and affects one of the most widely deployed workplace apps.
Update all Zoom software on Windows to the latest versions now.
1.Vulnerability Details
CVE ID – CVE-2026-53412
CVSS SCORE – 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EXPLOIT STATUS – No exploitation reported; found internally by Zoom Offensive Security
The flaw is improper input validation in the Zoom Desktop Client for Windows and the Zoom VDI Client for Windows. An unauthenticated attacker with network access can exploit it to take over a user’s account: no privileges, credentials, or user interaction are needed, and confidentiality, integrity, and availability are all fully impacted. Zoom published the bulletin (ZSB-26014) on 14 July 2026; revision 1.1 on 15 July 2026 removed Meeting SDK for Windows from the affected list. Zoom does not publish a formal CWE identifier for this CVE.
2. Affected Products & Fixed Versions
| Component | Vulnerable Versions | Fixed Build |
| Zoom Workplace for Windows | Before 7.0.0 | 7.0.0 |
| Zoom Workplace VDI Client for Windows (7.0.x) | Before 7.0.10 | 7.0.10 |
| Zoom Workplace VDI Client for Windows (6.6.x) | Before 6.6.15 | 6.6.15 |
| Zoom Workplace VDI Client for Windows (6.5.x) | Before 6.5.18 | 6.5.18 |
3. Other Notable CVEs
- CVE-2026-53410 (CVSS 7.0): Time-of-check to time-of-use race condition in the install and uninstall process of several Zoom Windows clients; lets an authenticated local user escalate privileges (ZSB-26012). Affects Zoom Workplace before 7.0.5, VDI Client and VDI Plugin before 6.5.17 and 6.6.14, Zoom Rooms before 7.0.5, and Remote Control for Zoom Contact Center before 7.0.0.
- CVE-2026-53409 (CVSS 7.8): Improper privilege management in Zoom Rooms for Windows before 7.1.0; lets an authenticated user escalate privileges via local access (ZSB-26011).
- CVE-2026-53411 (CVSS 7.8): Improper input validation in the Zoom Workplace VDI Plugin for Windows before 6.6.14; lets an authenticated user escalate privileges via local access (ZSB-26013).
4. Recommendations
- Inventory Windows endpoints and VDI estates running Zoom Workplace, VDI Client, VDI Plugin, or Zoom Rooms below the fixed versions, using your endpoint management or EDR console.
- Update Zoom Workplace for Windows to 7.0.0 or later from zoom.us/download, or push the package through your managed deployment tool such as Intune or SCCM.
- Update the VDI Client to 7.0.10, 6.6.15, or 6.5.18 in its branch, and the VDI Plugin to 6.6.14 or later, covering both virtual desktops and thin clients.
- Update Zoom Rooms for Windows to 7.1.0 or later to close the two local privilege escalation flaws patched in the same release.
5. Sources
- https://www.zoom.com/en/trust/security-bulletin/zsb-26014/
- https://www.zoom.com/en/trust/security-bulletin/zsb-26012/
- https://www.zoom.com/en/trust/security-bulletin/zsb-26011/
- https://www.zoom.com/en/trust/security-bulletin/zsb-26013/
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.