Junglewise Threat Intelligence

CVE-2026-53406: Zoom Contact Center privilege escalation in Remote Control for Windows

CVE-2026-53406 · Severity: high · CVSS 7.8 · Published 2026-06-12

Vendors: Zoom.

Executive brief

Zoom Contact Center for Windows contains a security flaw in its remote control feature that could allow a user with low-level access to a computer to gain higher-level administrative privileges. This could enable an unauthorized person to access sensitive data or modify system settings on the affected machine. Organizations using Zoom Contact Center should update their Windows client to version 7.0.0 or later to resolve this issue.

Technical details

A privilege escalation vulnerability exists in the Remote Control component of Zoom Contact Center for Windows (versions prior to 7.0.0) due to insufficient verification of data authenticity (CWE-345). An attacker with local access and low-level user privileges can exploit this flaw to execute commands or perform actions with elevated system permissions. The vulnerability is triggered when the application fails to properly validate the source or integrity of data processed by the remote control service. This issue has been addressed in version 7.0.0.

Affected products

  • Zoom Remote Control for Zoom Contact Center for Windows before 7.0.0

Timeline

  • 2026-06-09: advisory: Initial publication of Zoom Security Bulletin ZSB-26009
  • 2026-06-12: disclosed: CVE-2026-53406 published to NVD

References