7
CVE-2026-53410
- EPSS 0.09%
- Veröffentlicht 16.07.2026 21:11:44
- Zuletzt bearbeitet 17.08.2026 17:34:21
- CVE-Watchlists
- Unerledigt
Zoom Clients for Windows - Race Condition
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zoom ≫ Remote Control For Zoom Contact Center SwPlatformwindows Version < 7.0.0
Zoom ≫ Workplace Desktop SwPlatformwindows Version < 7.0.5
Zoom ≫ Workplace Virtual Desktop Infrastructure SwPlatformwindows Version < 6.5.17
Zoom ≫ Workplace Virtual Desktop Infrastructure SwPlatformwindows Version >= 6.6.0 < 6.6.14
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.007 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@zoom.us | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
https://www.zoom.com/en/trust/security-bulletin/zsb-26012