Time-of-check Time-of-use (TOCTOU) Race Condition in Zoom Video Communications, Inc. products - CVE-2026-53410

 

Time-of-check Time-of-use (TOCTOU) Race Condition in Zoom Video Communications, Inc. products - CVE-2026-53410

Published: July 14, 2026


Vulnerability identifier: #VU137492
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53410
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to a time-of-check to time-of-use race condition in the installation and uninstallation process when handling installation or uninstallation operations. A local user can trigger the race condition during installation or uninstallation to escalate privileges.


Affected software

Zoom Workplace Desktop App for Windows
Zoom Rooms Client for Windows
Virtual Desktop Infrastructure (VDI)
Remote Control for Zoom Contact Center for Windows

How to mitigate CVE-2026-53410

Install security update from vendor's website.

Zoom Workplace Desktop App for Windows - update to 7.0.5 38856
Zoom Rooms Client for Windows - update to 7.0.5
Virtual Desktop Infrastructure (VDI) - addressed in versions 6.5.17.26960, 6.6.14.26970
Remote Control for Zoom Contact Center for Windows - update to 7.0.0

External References

Related Security Bulletins