7.8
CVE-2026-53411
- EPSS 0.13%
- Veröffentlicht 16.07.2026 21:13:33
- Zuletzt bearbeitet 12.08.2026 00:03:23
- CVE-Watchlists
- Unerledigt
Zoom Workplace VDI Plugin for Windows - Improper Input Validation
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zoom ≫ Workplace Virtual Desktop Infrastructure SwPlatformwindows Version < 6.6.14
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.031 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| security@zoom.us | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://www.zoom.com/en/trust/security-bulletin/zsb-26013