Zoom Windows Apps Critical Unauthenticated Account Takeover (CVE-2026-53412) Plus Three Chained Local Privilege Escalation Flaws — Threadlinqs Intelligence
As of 2026-07-16, Zoom Windows Apps Critical Unauthenticated Account Takeover (CVE-2026-53412) Plus Three Chained Local Privilege Escalation Flaws is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-1393 · Severity: CRITICAL · CVSS: 9.8 · Status: PATCHED · Category: VULNERABILITY
Zoom disclosed CVE-2026-53412, a critical (CVSS 9.8) improper input validation flaw in Zoom Workplace for Windows, Windows VDI Client, and Meeting SDK for Windows that allows an unauthenticated,
On 2026-07-14, Zoom published four security bulletins (ZSB-26011 through ZSB-26014) covering vulnerabilities identified internally across its Windows application family. The headline issue, CVE-2026-53412 (ZSB-26014, CVSS v3.1 base score 9.8, CVSS v2 base score 10.0, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, CWE-20 Improper Input Validation), affects Zoom Workplace for Windows before 7.0.0, the Windows VDI Client before 7.0.10/6.6.15/6.5.18, and the Meeting SDK for Windows before 7.0.0. The flaw stems from insufficient validation of input reaching an authentication- or session-handling code path reachable over the network without prior authentication or user interaction, enabling account takeover. Because the affected components are widely deployed enterprise meeting clients, a working exploit chain would let an attacker impersonate a Zoom user, access meeting content, chat history, cloud recordings, and any SSO-linked resources exposed through the compromised account, without needing credentials or a phishing click.
Three companion CVEs, all requiring local/authenticated access, were patched in the same cycle and materially raise the risk of the environment even though they cannot be triggered remotely on their own: CVE-2026-53410 (ZSB-26012, CVSS 7.0, CWE-367 TOCTOU race condition during installer/uninstaller execution, affecting Zoom Workplace before 7.0.5, VDI Client/Plugin before 6.5.17/6.6.14, Zoom Rooms before 7.0.5, and Remote Control for Zoom Contact Center before 7.0.0) allows a local authenticated user to win a race between a privileged file/permission check and its use during install or uninstall to escalate privileges. CVE-2026-53409 (ZSB-26011, CVSS 7.8, CWE-269 Improper Privilege Management, affecting Zoom Rooms for Windows before 7.1.0) lets a local authenticated user escalate to a higher-privileged context due to insufficiently scoped access control on a Zoom Rooms component. CVE-2026-53411 (ZSB-26013, CVSS 7.8, CWE-20 Improper Input Validation, affecting the Zoom Workplace VDI Plugin for Windows before 6.6.14) permits a local authenticated user to escalate privileges by supplying malformed input the VDI plugin fails to validate before acting on it with elevated rights.
Chained together, an attacker who first achieves the network-based account takeover via CVE-2026-53412 and later obtains any form of local code execution on a shared or VDI endpoint (e.g., a kiosk, shared workstation, or virtual desktop pool) could pivot through CVE-2026-53409/53410/53411 to gain SYSTEM-level persistence on the Windows host itself, turning an account-level compromise into full endpoint compromise. This is particularly relevant for VDI and Zoom Rooms deployments, which are commonly multi-user, shared-session environments in enterprise, healthcare, education, and government settings. Because account takeover exposes SSO-linked cloud resources, an attacker could also plant additional cloud credentials or application access tokens on the hijacked account to retain access independent of the original session, without ever touching the Windows endpoint. As of disclosure, Zoom states there is no evidence any of the four vulnerabilities have been exploited in the wild, and no public proof-of-concept exploit code has surfaced. The vulnerabilities are not present in the CISA Known Exploited Vulnerabilities (KEV) catalog as of 2026-07-15. Zoom credits its own internal security team with discovery; no external researcher or bug-bounty submitter has been publicly named. Independent CVE-tracking and security-news outlets (Tenable, SecurityOnline, Rankiteo) republished and cross-indexed the same four CVEs within a day of disclosure, each confirming the CVSS scores, affected version ranges, and the no-exploitation/no-PoC status without surfacing additional technical detail beyond Zoom's bulletins.
Remediation is a straightforward update to the fixed client/plugin/SDK versions distributed through Zoom's standard auto-update channel and ente
Weaknesses (CWE)
CWE-20, CWE-367, CWE-269
Target sectors: technology, government administration, health, education, finance, professional-services, telecoms
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-53412, CVE-2026-53410, CVE-2026-53409, CVE-2026-53411, T1190, T1078, T1133, T1539, T1212, T1550, T1068, T1548, T1098, T1098