Technology

Zoom users beware: Serious vulnerability in the Windows client

Meeting platform Zoom has warned of a serious security flaw in its Windows software that could allow user accounts to be taken over under certain circumstances.

Account takeover possible

Both the desktop client and the software development kit (SDK) for Windows are affected. The company itself classifies the vulnerability as critical and recommends that all users install the currently available security updates immediately. The internally discovered vulnerability is identified as CVE-2026-53412 and received a CVSS severity score of 9.8 out of 10. After Declarations Zooms is an input validation error. An attacker could exploit this over the network without having to authenticate first and thereby gain control of a user account.

The vulnerability affects Zoom Workplace for Windows in versions before 7.0.0, the Windows VDI client in versions before 7.0.10, 6.6.15 and 6.5.18, and the Meeting SDK for Windows before version 7.0.0. Zoom Workplace, formerly Zoom, bundles features such as video conferencing, group chat, VoIP telephony, calendar, email, document collaboration, whiteboards and AI-powered productivity tools. The application is used by millions of private users and companies worldwide.

The provider deliberately did not publish technical details about the security gap. Such information is often initially withheld in order not to provide potential attackers with additional clues until all users have updated their systems.

Further gaps closed

In addition to the vulnerability classified as critical, the current updates eliminate three other high-severity security issues. This includes the CVE-2026-53410 vulnerability, which affects various Windows components of Zoom and could allow a locally logged in user to gain higher privileges during installation or uninstallation. Also fixed were CVE-2026-53409, an incorrect rights management issue in Zoom Rooms for Windows, and CVE-2026-53411, another input validation vulnerability in the Zoom Workplace VDI plugin.

Both could be abused by authenticated users with local access for privilege escalation. According to current knowledge, there is no evidence that any of the security gaps that have now been closed have already been exploited in attacks. However, Zoom strongly advises all users to install the updates provided promptly in order to minimize the risk of possible attacks.

Recent Posts

Best Hypervisors for Enterprise Virtualization

If you've been put in charge of picking the next hypervisor for your data center,…

4 hours ago

Apple: iPhone keynote date set! The motto is “Surprise and Shine”

Expensive folding cell phones, cameras in headphones and a change in boss: Apple is introducing…

10 hours ago

Meta pays $18 billion, rebuilds Instagram, locks out teenagers at night

Meta ends a process about addiction design at Facebook with a billion-dollar payment and conditions:…

10 hours ago

Bill Gates warns of AI danger: Tech industry trivializes the risks

Mass unemployment, cyberattacks and bioterrorism: Bill Gates paints a bleak picture of artificial intelligence in…

10 hours ago

Beware of ToxicPanda: This Android Trojan blocks Google Play

A new version of the Android Trojan ToxicPanda threatens users of financial and crypto applications…

10 hours ago

YouTube: New Liquid Glass look & Live Activities planned for iOS apps

Google is apparently planning a design update for YouTube and YouTube Music on iOS. Discovered…

10 hours ago