Critical Zoom Vulnerability Could Allow Account Takeover Without User Interaction

Zoom has patched a critical security vulnerability in its Windows software that could allow an unauthenticated attacker to take over user accounts remotely. The flaw, tracked as CVE-2026-53412, carries a CVSS score of 9.8.

The vulnerability affects Zoom Workplace Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. It stems from improper input validation that could be exploited over the network without requiring any user interaction or privileges.

The severity of the flaw is amplified by Zoom’s extensive user base of more than 300 million daily active users and hundreds of thousands of business customers. An attacker successfully exploiting the vulnerability could potentially access meetings, contacts, and account settings without the victim’s knowledge.

In addition to the critical account takeover vulnerability, Zoom also patched three other high-severity privilege escalation issues affecting various Windows components. These could allow an attacker with local access to elevate their privileges on affected systems.

Security experts advise all Zoom users on Windows to update to the latest version immediately. The patched versions include Zoom Workplace for Windows 7.0.5 and later, along with corresponding updates for VDI and Rooms clients.

The patches were released as part of Zoom’s regular security update cycle, with the company crediting internal security researchers for discovering the vulnerabilities.

References

This article was adapted from The Hacker News. Read the original here.