All stories

Unauthenticated attackers can hijack Zoom accounts through critical vulnerability in Windows software

馃毃 An unauthenticated attacker can hijack accounts via network access due to a critical flaw in Zoom's Windows software. This affects the standard Workplace client, VDI clients, and the Meeting SDK. Update your desktop applications immediately to mitigate this risk.

Summary

Zoom has issued a warning regarding a critical vulnerability affecting its Windows-based products. The flaw, tracked as CVE-2026-53412, allows an unauthenticated party to conduct account takeovers through network access.

The issue was discovered internally by Zoom's security team. While the company has released patches to address the vulnerability, specific technical details regarding the root cause remain undisclosed in their official advisory.

Technical details

The vulnerability is categorized as an improper input validation issue. According to the security advisory, this flaw can be exploited by an unauthenticated user to gain control of a Zoom account via network access.

Because the flaw involves how the software validates incoming data, it presents a significant risk to organizations relying on the Windows desktop client for video meetings, group chat, and VoIP communications.

Affected products and fixed versions

The vulnerability impacts several specific iterations of Zoom's Windows software. Users should verify their current version numbers against the following list:

Product Affected Versions Fixed Version
Zoom Workplace for Windows Before 7.0.0 7.0.0 or later
Zoom VDI Client for Windows Before 7.0.10, 6.6.15, and 6.5.18 7.0.10, 6.6.15, or 6.5.18 (depending on branch)
Zoom Meeting SDK for Windows Before 7.0.0 7.0.0 or later

In addition to the primary account takeover flaw, Zoom's latest security updates also address several high-severity privilege escalation vulnerabilities:

  • CVE-2026-53410: A TOCTOU (time-of-check to time-of-use) race condition affecting Zoom Workplace for Windows (before 7.0.5), VDI Client/Plugin (before 6.5.17/6.6.14), and Zoom Rooms for Windows (before 7.0.5). This could allow an authenticated local user to escalate privileges during installation or uninstallation.
  • CVE-2026-53409: An improper privilege management flaw in Zoom Rooms for Windows (before 7.1.0) that allows an authenticated user with local access to escalate privileges.
  • CVE-2026-53411: An improper input validation flaw in the Zoom Workplace VDI Plugin for Windows (before 6.6.14) that could allow an authenticated user with local access to escalate privileges.

Exploitation status

There are currently no indications that any of these vulnerabilities are being exploited in active attacks. The discovery was made through internal security testing rather than external observation.

Defender guidance

The primary defense against these vulnerabilities is the immediate application of Zoom's latest updates.

  • For standard users: Update Zoom Workplace for Windows to version 7.0.0 or higher.
  • For VDI environments: Ensure the Windows VDI Client is updated to at least version 7.0.10, 6.6.15, or 6.5.18, depending on your specific deployment branch.
  • For developers: Update the Meeting SDK for Windows to version 7.0.0 or later.

Monitor network traffic for unusual patterns associated with unauthenticated access attempts toward Zoom client endpoints, though specific indicators of compromise have not yet been released by the vendor.

Sources

  1. https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability/
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -