Junglewise Threat Intelligence

CVE-2026-53411: Zoom Workplace VDI Plugin privilege escalation in Windows installer

CVE-2026-53411 · Severity: high · CVSS 7.8 · Published 2026-07-16

Executive brief

A security vulnerability exists in the installation and uninstallation process of the Zoom Workplace VDI Plugin for Windows. This flaw could allow a person who already has a standard user account on a computer to gain administrative-level control over that system. Such an exploit could lead to unauthorized access to sensitive data or the ability to disable security software.

Technical details

A time-of-check to time-of-use (TOCTOU) race condition exists within the installation and uninstallation routines of the Zoom Workplace VDI Plugin for Windows. The vulnerability is rooted in improper input validation during these processes. An attacker with local access and low-level user privileges can exploit this race condition to manipulate files or processes, leading to an escalation of privilege to a higher level (such as SYSTEM). The issue affects versions prior to 6.6.14 and has been addressed in the latest updates.

Affected products

  • Zoom Communications Zoom Workplace VDI Plugin prior to 6.6.14

Timeline

  • 2026-07-14: advisory: Initial publication by Zoom (ZSB-26013)
  • 2026-07-16: disclosed: NVD publication date

References