CVE-2026-53411

EUVD-2026-45046
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 3.04%
Affected Products (NVD)
VendorProductVersion
zoomworkplace_virtual_desktop_infrastructure
𝑥
< 6.6.14
𝑥
= Vulnerable software versions