CRITICAL🇵🇱 Wersja polska

CVE-2026-53412

CVSS 9.8v3.1pub. 2026-07-16upd. 2026-08-11

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Zoom Workplace Desktop

    APP
    Zoom
    < 7.0.0
  • Zoom Workplace Virtual Desktop Infrastructure

    APP
    Zoom
    6.5.0 – 6.5.18 (excl.)6.6.0 – 6.6.15 (excl.)7.0.0 – 7.0.10 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-30903CRITICAL9.6PL ✓same product

Zoom Workplace dla Windows — privilege escalation przez kontrolę ścieżki pliku w funkcji Mail

CVE-2025-49457CRITICAL9.6PL ✓same product

Untrusted search path w klientach Zoom dla Windows — privilege escalation przez sieć

CVE-2026-53410HIGH7.0PL ✓same product

TOCTOU race condition w Zoom Client dla Windows — privilege escalation

CVE-2026-53411HIGH7.8PL ✓same product

Privilege escalation przez TOCTOU w Zoom Client dla Windows

CVE-2026-30905HIGH7.8same product

External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before vers...