Zoom Patches Critical Account Takeover Vulnerability in Windows Client

Zoom has released security updates addressing a critical vulnerability in its Windows desktop client and software development kit that could allow an unauthenticated attacker to hijack user accounts.

The flaw, tracked as CVE-2026-53412, carries a CVSS severity score of 9.8 out of 10. Discovered internally by Zoom, the issue is described as an improper input validation vulnerability affecting Zoom Workplace for Windows before version 7.0.0, the Windows VDI Client before versions 7.0.10, 6.6.15, and 6.5.18, and the Meeting SDK for Windows before version 7.0.0.

Zoom Workplace — the company’s desktop collaboration application used by millions for video meetings, group chat, VoIP calling, calendar, email, document collaboration, whiteboards, and AI-powered productivity features — is widely deployed across enterprise environments globally.

According to Zoom’s security advisory, the improper input validation issue “may allow an unauthenticated user to conduct an account takeover via network access.” The vendor has not disclosed technical details about the exploit vector but recommends users apply the latest updates immediately.

The same patch batch also addresses three additional high-severity vulnerabilities:

  • CVE-2026-53410 — a TOCTOU race condition in Zoom Workplace for Windows, VDI Client, VDI Plugin, Zoom Rooms, and Remote Control for Zoom Contact Center, potentially allowing privilege escalation during installation or uninstallation.
  • CVE-2026-53409 — improper privilege management in Zoom Rooms for Windows before version 7.1.0 that could allow authenticated local users to escalate privileges.
  • CVE-2026-53411 — improper input validation in the Zoom Workplace VDI Plugin for Windows before version 6.6.14, also enabling local privilege escalation.

At this time, there are no reports of active exploitation of any of these vulnerabilities in the wild. Users are advised to update their Zoom clients to the latest available versions.

References


This article was originally reported by Bleeping Computer. Rewritten and published by The Coolest Info.