VDB
CVE-2026-53411
CVE-2026-53411
PUBLISHED
CVSS 7.8 HIGH
Reported by Zoom · Published July 16, 2026
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
Risk Scores
CVSS 3.1
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zoom Communications | Zoom Workplace VDI Plugin | 0 |
| Zoom Communications | Zoom Workplace VDI Plugin | 0, 0 |
Timeline
- Jan 1, 2026 CVE Published
- Jul 17, 2026 CVE Updated