NCSC-2026-0249 [1.00] [M/M] Vulnerabilities fixed in Zoom
Zoom has fixed vulnerabilities in Zoom Client for Windows, Zoom Rooms for Windows, and other Zoom Windows products such as the Windows Desktop Client, VDI Client, and Meeting SDK. The vulnerabilities include a TOCTOU race condition that can be exploited by an authenticated local user to escalate privileges. Additionally, there is improper privilege management in Zoom Rooms for Windows (versions earlier than 7.1.0), allowing authenticated local users to gain higher access rights than intended. Furthermore, there are issues with improper input validation in the Zoom Windows Desktop Client, VDI Client, and Meeting SDK, allowing unauthenticated attackers to gain control over user accounts via network access. These vulnerabilities arise from insufficient validation of input data and inadequate enforcement of privilege boundaries within the applications.
CSIRTS triage
- What
- Vulnerabilities allow authenticated local users to escalate privileges and unauthenticated attackers to gain control over user accounts.
- Who is affected
- Authenticated local users of Zoom Rooms for Windows and unauthenticated users accessing Zoom Windows products.
- Urgency
- Remediation is important as these vulnerabilities can lead to significant security breaches.
- Action
- Users should update to the latest version of Zoom.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Zoom Client for Windows
Get an email when a new Zoom Client for Windows advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0249
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-534100.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-534090.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-534110.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all scored CVEs.
- Low exploitation riskCVE-2026-534120.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-53410 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53409 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53411 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53412 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Zoom Video Communications Rooms: Multiple vulnerabilitiescert-bund
- criticalCVE-2026-53412: Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and…nvd
- highCVE-2026-53411: A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation …nvd
- highCVE-2026-53410: A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation …nvd
- highCVE-2026-53409: Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an auth…nvd
- unknownZoom Products Multiple Vulnerabilitieshkcert
Recent advisories for Zoom
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Zoom Video Communications Rooms: Multiple vulnerabilitiescert-bund · 2026-07-17
- criticalCVE-2026-53412: Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and…nvd · 2026-07-16
- highCVE-2026-53411: A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation …nvd · 2026-07-16
- highCVE-2026-53410: A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation …nvd · 2026-07-16
- highCVE-2026-53409: Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an auth…nvd · 2026-07-16
- unknownZoom security advisory (AV26-707)cccs · 2026-07-16
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30