Zoom Windows Apps Critical Unauthenticated Account Takeover (CVE-2026-53412) Plus Three Chained Local Privilege Escalation Flaws

Zoom Windows Apps Critical Unauthenticated Account Takeover (TL-2026-1393), also tracked as Zoom Windows Account Takeover, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-16. It has no confirmed attribution, affects Zoom Zoom Workplace for Windows, references 4 CVEs (CVE-2026-53412, CVE-2026-53410, CVE-2026-53409), maps to 16 MITRE ATT&CK techniques (T1068, T1078, T1087), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-1393

Threat ID
TL-2026-1393
Also known as
Zoom Windows Account Takeover, ZSB-26014
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
2026-07-16
Last reviewed
2026-07-16
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, health, education, finance, professional-services, telecoms
Target regions
Global
Detection rules
9
Indicators of compromise
18

Zoom disclosed CVE-2026-53412, a critical (CVSS 9.8) improper input validation flaw in Zoom Workplace for Windows, Windows VDI Client, and Meeting SDK for Windows that allows an unauthenticated, network-adjacent attacker to take over a user account with no interaction required. The same patch cycle (ZSB-26011 through ZSB-26014) fixed three related high-severity local privilege-escalation issues (CVE-2026-53409, CVE-2026-53410, CVE-2026-53411) in Zoom Rooms, VDI Client/Plugin, and Remote Control for Zoom Contact Center. Zoom found all four issues internally; there is no evidence of in-the-wild exploitation and no public PoC as of disclosure.

How Zoom Windows Apps Critical Unauthenticated Account Takeover works

On 2026-07-14, Zoom published four security bulletins (ZSB-26011 through ZSB-26014) covering vulnerabilities identified internally across its Windows application family. The headline issue, CVE-2026-53412 (ZSB-26014, CVSS v3.1 base score 9.8, CVSS v2 base score 10.0, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, CWE-20 Improper Input Validation), affects Zoom Workplace for Windows before 7.0.0, the Windows VDI Client before 7.0.10/6.6.15/6.5.18, and the Meeting SDK for Windows before 7.0.0. The flaw stems from insufficient validation of input reaching an authentication- or session-handling code path reachable over the network without prior authentication or user interaction, enabling account takeover. Because the affected components are widely deployed enterprise meeting clients, a working exploit chain would let an attacker impersonate a Zoom user, access meeting content, chat history, cloud recordings, and any SSO-linked resources exposed through the compromised account, without needing credentials or a phishing click.

Three companion CVEs, all requiring local/authenticated access, were patched in the same cycle and materially raise the risk of the environment even though they cannot be triggered remotely on their own: CVE-2026-53410 (ZSB-26012, CVSS 7.0, CWE-367 TOCTOU race condition during installer/uninstaller execution, affecting Zoom Workplace before 7.0.5, VDI Client/Plugin before 6.5.17/6.6.14, Zoom Rooms before 7.0.5, and Remote Control for Zoom Contact Center before 7.0.0) allows a local authenticated user to win a race between a privileged file/permission check and its use during install or uninstall to escalate privileges. CVE-2026-53409 (ZSB-26011, CVSS 7.8, CWE-269 Improper Privilege Management, affecting Zoom Rooms for Windows before 7.1.0) lets a local authenticated user escalate to a higher-privileged context due to insufficiently scoped access control on a Zoom Rooms component. CVE-2026-53411 (ZSB-26013, CVSS 7.8, CWE-20 Improper Input Validation, affecting the Zoom Workplace VDI Plugin for Windows before 6.6.14) permits a local authenticated user to escalate privileges by supplying malformed input the VDI plugin fails to validate before acting on it with elevated rights.

Chained together, an attacker who first achieves the network-based account takeover via CVE-2026-53412 and later obtains any form of local code execution on a shared or VDI endpoint (e.g., a kiosk, shared workstation, or virtual desktop pool) could pivot through CVE-2026-53409/53410/53411 to gain SYSTEM-level persistence on the Windows host itself, turning an account-level compromise into full endpoint compromise. This is particularly relevant for VDI and Zoom Rooms deployments, which are commonly multi-user, shared-session environments in enterprise, healthcare, education, and government settings. Because account takeover exposes SSO-linked cloud resources, an attacker could also plant additional cloud credentials or application access tokens on the hijacked account to retain access independent of the original session, without ever touching the Windows endpoint. As of disclosure, Zoom states there is no evidence any of the four vulnerabilities have been exploited in the wild, and no public proof-of-concept exploit code has surfaced. The vulnerabilities are not present in the CISA Known Exploited Vulnerabilities (KEV) catalog as of 2026-07-15. Zoom credits its own internal security team with discovery; no external researcher or bug-bounty submitter has been publicly named. Independent CVE-tracking and security-news outlets (Tenable, SecurityOnline, Rankiteo) republished and cross-indexed the same four CVEs within a day of disclosure, each confirming the CVSS scores, affected version ranges, and the no-exploitation/no-PoC status without surfacing additional technical detail beyond Zoom's bulletins.

Remediation is a straightforward update to the fixed client/plugin/SDK versions distributed through Zoom's standard auto-update channel and enterprise MSI/PKG deployment mechanisms. Because CVE-2026-53412 requires no authentication and no user interaction, unpatched exposed Zoom Windows clients should be treated as an urgent patch-management priority, particularly for organizations that have disabled Zoom's automatic update mechanism in favor of managed enterprise deployment (a common pattern that can silently widen the exposure window).

MITRE ATT&CK techniques used in TL-2026-1393

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Discovery

T1087 Account Discovery

Persistence

T1098 Account Manipulation

Collection

T1119 Automated Collection; T1213 Data from Information Repositories

Defense Evasion

T1211 Exploitation for Stealth

Credential Access

T1212 Exploitation for Credential Access; T1539 Steal Web Session Cookie

Impact

T1531 Account Access Removal

lateral-movement

T1550 Use Alternate Authentication Material

Resource Development

T1586 Compromise Accounts

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Zoom Windows Apps Critical Unauthenticated Account Takeover

  • Zoom — Zoom Workplace for Windows
    Vulnerable versions: before 7.0.0 (CVE-2026-53412); before 7.0.5 (CVE-2026-53410)
    Fixed in: 7.0.5
  • Zoom — Windows VDI Client
    Vulnerable versions: before 7.0.10; before 6.6.15; before 6.5.18 (CVE-2026-53412); before 6.5.17; before 6.6.14 (CVE-2026-53410)
    Fixed in: 7.0.10; 6.6.15; 6.5.18
  • Zoom — Meeting SDK for Windows
    Vulnerable versions: before 7.0.0
    Fixed in: 7.0.0
  • Zoom — Zoom Workplace VDI Plugin for Windows
    Vulnerable versions: before 6.6.14; before 6.5.17
    Fixed in: 6.6.14
  • Zoom — Zoom Rooms for Windows
    Vulnerable versions: before 7.0.5 (CVE-2026-53410); before 7.1.0 (CVE-2026-53409)
    Fixed in: 7.1.0
  • Zoom — Remote Control for Zoom Contact Center
    Vulnerable versions: before 7.0.0
    Fixed in: 7.0.0

Remediation for Zoom Windows Apps Critical Unauthenticated Account Takeover

Patches

  • Zoom Workplace for Windows >= 7.0.0 (CVE-2026-53412), >= 7.0.5 (CVE-2026-53410)
  • Windows VDI Client >= 7.0.10 / 6.6.15 / 6.5.18 (CVE-2026-53412), >= 6.5.17 / 6.6.14 (CVE-2026-53410)
  • Meeting SDK for Windows >= 7.0.0 (CVE-2026-53412)
  • Zoom Rooms for Windows >= 7.0.5 (CVE-2026-53410), >= 7.1.0 (CVE-2026-53409)
  • Remote Control for Zoom Contact Center >= 7.0.0 (CVE-2026-53410)
  • Zoom Workplace VDI Plugin for Windows >= 6.6.14 (CVE-2026-53411)

Immediate actions

  • Update Zoom Workplace for Windows to version 7.0.0 or later
  • Update Windows VDI Client to version 7.0.10, 6.6.15, or 6.5.18 or later depending on branch
  • Update Meeting SDK for Windows to version 7.0.0 or later
  • Update Zoom Workplace for Windows to version 7.0.5 or later to remediate CVE-2026-53410
  • Update VDI Client/Plugin to version 6.5.17 or 6.6.14 or later to remediate CVE-2026-53410 and CVE-2026-53411
  • Update Zoom Rooms for Windows to version 7.0.5 (CVE-2026-53410) and 7.1.0 (CVE-2026-53409) or later
  • Update Remote Control for Zoom Contact Center to version 7.0.0 or later

Workarounds

  • Where immediate patching is not possible, restrict network reachability to Zoom Windows client endpoints via network segmentation
  • Disable or restrict shared/multi-user login on Zoom Rooms and VDI endpoints until patched

Longer-term hardening

  • Re-enable and enforce Zoom's automatic update mechanism on managed Windows fleets instead of relying solely on manual MSI pushes
  • Restrict network exposure of Zoom Windows client authentication/session-handling ports to only necessary paths
  • Harden shared/VDI/kiosk Zoom Rooms endpoints against local privilege escalation via least-privilege service accounts
  • Monitor for anomalous Zoom session/account activity indicative of takeover (impossible-travel logins, unexpected device registrations)
  • Include Zoom desktop client and VDI plugin versions in routine enterprise vulnerability and patch-compliance scanning
  • Review SSO-linked application access tokens and cloud credentials tied to Zoom accounts for unauthorized additions after any suspected takeover

CVEs associated with Zoom Windows Apps Critical Unauthenticated Account Takeover

CVE-2026-53412, CVE-2026-53410, CVE-2026-53409, CVE-2026-53411

Weaknesses (CWE) in Zoom Windows Apps Critical Unauthenticated Account Takeover

CWE-20, CWE-367, CWE-269

Timeline of Zoom Windows Apps Critical Unauthenticated Account Takeover

  • Fixed versions of Zoom Workplace for Windows, Windows VDI Client, Meeting SDK for Windows, Zoom Rooms for Windows, VDI Plugin, and Remote Control for Zoom Contact Center made available via ZSB-26011 through ZSB-26014.
  • Zoom publishes security bulletins ZSB-26011 through ZSB-26014 disclosing four Windows client vulnerabilities, discovered internally, with no evidence of exploitation.
  • CISA Known Exploited Vulnerabilities catalog (1,644 entries as of the 2026-07-15 release) checked and confirmed not to include any of the four CVEs, consistent with Zoom's no-exploitation statement.
  • Rankiteo publishes further technical analysis of all four CVEs, reiterating the attack scenarios and noting exposure across technology, education, healthcare, and enterprise sectors relying on Zoom.
  • Tenable and other CVE aggregator databases index CVE-2026-53412, recording CVSS v2 base score 10.0 and CVSS v3 base score 9.8 alongside the affected product list.
  • SecurityOnline publishes an independent technical writeup analyzing CVE-2026-53412 and the three companion privilege-escalation CVEs, confirming CWE classes and affected version ranges.
  • BleepingComputer publishes coverage of the critical account takeover vulnerability, summarizing the four patched CVEs.
  • Threat processed and documented by the Threadlinqs Intelligence pipeline as TL-2026-1393.

Sources cited for Zoom Windows Apps Critical Unauthenticated Account Takeover

Threats related to Zoom Windows Apps Critical Unauthenticated Account Takeover

Detection coverage for TL-2026-1393

As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1393 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats