Technology

Zoom users beware: Serious vulnerability in the Windows client

Meeting platform Zoom has warned of a serious security flaw in its Windows software that could allow user accounts to be taken over under certain circumstances.

Account takeover possible

Both the desktop client and the software development kit (SDK) for Windows are affected. The company itself classifies the vulnerability as critical and recommends that all users install the currently available security updates immediately. The internally discovered vulnerability is identified as CVE-2026-53412 and received a CVSS severity score of 9.8 out of 10. After Declarations Zooms is an input validation error. An attacker could exploit this over the network without having to authenticate first and thereby gain control of a user account.

The vulnerability affects Zoom Workplace for Windows in versions before 7.0.0, the Windows VDI client in versions before 7.0.10, 6.6.15 and 6.5.18, and the Meeting SDK for Windows before version 7.0.0. Zoom Workplace, formerly Zoom, bundles features such as video conferencing, group chat, VoIP telephony, calendar, email, document collaboration, whiteboards and AI-powered productivity tools. The application is used by millions of private users and companies worldwide.

The provider deliberately did not publish technical details about the security gap. Such information is often initially withheld in order not to provide potential attackers with additional clues until all users have updated their systems.

Further gaps closed

In addition to the vulnerability classified as critical, the current updates eliminate three other high-severity security issues. This includes the CVE-2026-53410 vulnerability, which affects various Windows components of Zoom and could allow a locally logged in user to gain higher privileges during installation or uninstallation. Also fixed were CVE-2026-53409, an incorrect rights management issue in Zoom Rooms for Windows, and CVE-2026-53411, another input validation vulnerability in the Zoom Workplace VDI plugin.

Both could be abused by authenticated users with local access for privilege escalation. According to current knowledge, there is no evidence that any of the security gaps that have now been closed have already been exploited in attacks. However, Zoom strongly advises all users to install the updates provided promptly in order to minimize the risk of possible attacks.

Recent Posts

Apple could be banned from buying Chinese memory chips

Due to the global shortage of memory chips, Apple is looking for new suppliers in…

1 hour ago

Assassin’s Creed Hexe: New leak reveals information about gameplay, price and much more.

Ubisoft is working on the next big title in its well-known video game series with…

1 hour ago

Steam games on SSD: hobbyist builds his own retro PC cartridges

A PC gamer has found a way to bring the feel of classic cartridges into…

1 hour ago

Apple lawsuit against OpenAI: Embarrassing email glitch escalated the dispute

Apple is suing OpenAI for allegedly stealing secret hardware information. Current documents now show the…

1 hour ago

Sonos fixes controversial app: Update brings back tab navigation

Sonos is currently releasing a new app update: The classic tab navigation returns, speakers can…

1 hour ago

Windows 11: Bug fix shrinks some 500 GB system files to just a few MB

A bug in Windows 11 caused the size of a certain system file to increase…

1 hour ago