Junglewise Threat Intelligence

CVE-2026-53410: Zoom Clients for Windows privilege escalation in installer

CVE-2026-53410 · Severity: high · CVSS 7 · Published 2026-07-16

Executive brief

A security vulnerability exists in several Zoom applications for Windows, including Zoom Workplace and Zoom Rooms, during their installation and uninstallation processes. A local user with limited access to a computer could exploit a timing flaw to gain higher-level administrative privileges. This could allow an unauthorized person to gain full control over the affected system, potentially leading to data theft or the installation of malicious software.

Technical details

A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability (CWE-367) exists within the installer and uninstaller components of various Zoom Windows clients. The flaw occurs when the application performs a security check on a file or resource but the state of that resource changes before it is actually used. An authenticated local attacker with low privileges can exploit this race condition to execute arbitrary code or modify system files with elevated privileges. The attack requires local access and specific timing to succeed (High Attack Complexity). Zoom has released updates for affected products, including Zoom Workplace, VDI clients, and Zoom Rooms, to mitigate this issue.

Affected products

  • Zoom Video Communications, Inc. Zoom Workplace for Windows before 7.0.5
  • Zoom Video Communications, Inc. Zoom Workplace VDI Client for Windows before 6.5.17, 6.6.14
  • Zoom Video Communications, Inc. Zoom Workplace VDI plugin for Windows before 6.5.17, 6.6.14
  • Zoom Video Communications, Inc. Zoom Rooms for Windows before 7.0.5
  • Zoom Video Communications, Inc. Remote Control for Zoom Contact Center for Windows before 7.0.0

Timeline

  • 2026-07-14: advisory: Initial publication of ZSB-26012 by Zoom.
  • 2026-07-16: disclosed: CVE-2026-53410 published to the NVD dataset.

References