CVE-2026-53410: Zoom Clients for Windows - Race Condition
Published Jul 16, 2026
·Updated
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
Affected Software
6 affected components
Zoom Zoom Clients for Windows
Zoom Remote Control For Zoom Contact Center Windows<7.0.0
Zoom Rooms Windows<7.0.5
Zoom Workplace Desktop Windows<7.0.5
Zoom Workplace Virtual Desktop Infrastructure Windows<6.5.17
Zoom Workplace Virtual Desktop Infrastructure Windows>=6.6.0<6.6.14
Event History
Jul 16, 2026
CVE Published
via MITRE·09:11 PM
Data Sourced
via MITRE·09:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-53410?
CVE-2026-53410 has a high severity rating of 7.
2
What type of vulnerability is CVE-2026-53410?
CVE-2026-53410 is classified as a race condition vulnerability.
3
How can CVE-2026-53410 be exploited?
CVE-2026-53410 can be exploited by an authenticated local user during the installation or uninstallation of Zoom Clients for Windows.
4
What can I do to mitigate the risks of CVE-2026-53410?
To mitigate the risks of CVE-2026-53410, ensure that Zoom Clients for Windows are regularly updated to the latest version.
5
Who is affected by CVE-2026-53410?
CVE-2026-53410 affects users of Zoom Clients for Windows who have local access to the system.