Zoom has disclosed a critical security vulnerability affecting its Windows applications. The flaw could allow unauthenticated attackers to completely take over user accounts.
Video communications provider Zoom has warned of a critical security vulnerability affecting its Desktop Client and Software Development Kit (SDK) for Windows. The internally discovered flaw, tracked as CVE-2026-53412, received a CVSS score of 9.8 out of 10, making it one of the most severe vulnerabilities under the Common Vulnerability Scoring System.
The issue affects the following products:
- Zoom Workplace for Windows prior to version 7.0.0
- Zoom VDI Client for Windows prior to versions 7.0.10, 6.6.15, and 6.5.18
- Zoom Meeting SDK for Windows prior to version 7.0.0
In its official security advisory, Zoom did not disclose technical details about how the vulnerability can be exploited. The company described the issue as improper input validation and stated:
“Improper input validation in the Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.”
Zoom
To reduce the associated risk, Zoom strongly recommends that all users immediately install the latest software updates available through its official distribution channels.
Additional High-Severity Vulnerabilities Patched
Alongside the critical vulnerability, Zoom’s latest security update also addresses three additional high-severity flaws:
- CVE-2026-53410: A race condition affecting Zoom Workplace for Windows, the Zoom VDI Client, Zoom Rooms, and the associated plugin. A locally authenticated attacker could exploit the flaw during installation or uninstallation to gain elevated system privileges.
- CVE-2026-53409: An improper privilege management vulnerability in Zoom Rooms for Windows that allows an authenticated local user to escalate privileges.
- CVE-2026-53411: An improper input validation flaw in the Zoom VDI Plugin for Windows that could allow a locally authenticated user to elevate privileges on the affected system.
No Evidence of Active Exploitation
Zoom’s Windows applications are used by millions of individuals and organizations worldwide for video conferencing, team collaboration, VoIP communications, and document sharing. At the time the security advisory was published, Zoom stated that it had no evidence or reports indicating that any of the patched vulnerabilities had been exploited in real-world attacks.
(ll)