news.mlab.sh
Back to the feed
vulnerability

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

High
Summary

Zoom has released critical security patches to address a series of vulnerabilities in its Windows-based products, including Zoom Workplace, Zoom VDI Client, and Zoom Rooms. These flaws could allow attackers to gain unauthorized access and escalate privileges, potentially leading to account takeover. Users are strongly advised to update immediately to mitigate the risk.

Zoom has released security updates to address a critical vulnerability in its Windows-based products, including Zoom Workplace, Zoom VDI Client, and Zoom Rooms. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), stems from improper input validation and could enable an unauthenticated user to conduct an account takeover via network access. Additionally, three other high-severity flaws have been patched: CVE-2026-53411 (CVSS score: 7.8) related to Zoom Workplace VDI Plugin, CVE-2026-53410 (CVSS score: 7.0) a TOCTOU race condition in client installation, and CVE-2026-53409 (CVSS score: 7.8) concerning Zoom Rooms privilege escalation. These flaws affect various Zoom products including Zoom Workplace for Windows before version 7.0.5, Zoom Workplace VDI Client for Windows before 6.5.17 and 6.6.14, Zoom Workplace VDI plugin for Windows before 6.5.17 and 6.6.14, and Zoom Rooms for Windows before 7.0.5. Remote Control for Zoom Contact Center for Windows is also impacted by version 7.0.0. As of now, there’s no evidence of active exploitation in the wild, but prompt patching is crucial to prevent potential attacks. Users should install the latest updates to ensure their systems are protected.

Read the full article at The Hacker News