TOCTOU Race Condition in Zoom Clients for Windows by Zoom
CVE-2026-53411

7.8HIGH

Key Information:

Vendor
CVE Published:
16 July 2026

What is CVE-2026-53411?

A time-of-check to time-of-use (TOCTOU) race condition exists in the installation and uninstallation processes of specific Zoom Clients for Windows. This vulnerability could potentially allow an authenticated local user to escalate their privileges, creating a significant security risk. It highlights the importance of addressing race conditions in software development to prevent unauthorized access.

Affected Version(s)

Zoom Workplace VDI Plugin Windows 0 < 6.6.14

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.