CVE-2026-53410

EUVD-2026-45045
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
TOCTOU
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 0.79%
Affected Products (NVD)
VendorProductVersion
zoomremote_control_for_zoom_contact_center
𝑥
< 7.0.0
zoomrooms
𝑥
< 7.0.5
zoomworkplace_desktop
𝑥
< 7.0.5
zoomworkplace_virtual_desktop_infrastructure
𝑥
< 6.5.17
zoomworkplace_virtual_desktop_infrastructure
6.6.0 ≤
𝑥
< 6.6.14
𝑥
= Vulnerable software versions