A recently disclosed vulnerability (CVE-2026-53412) that affects Zoom Workplace for Windows and Zoom Workplace VDI Client for Windows and may allow an unauthenticated remote attacker to take over a user account via network access.
Severity level:
CVSS Score: 9.8/Critical.
Description:
CVE-2026-53412 is a critical vulnerability caused by improper input validation in Zoom Workplace for Windows and Zoom Workplace VDI Client for Windows. An unauthenticated attacker can exploit the flaw remotely over a network to perform an account takeover.
Affected Versions:
- Zoom Workplace for Windows before 7.0.0.
- Zoom Workspace VDI client for Windows before (7.0.10, 6.6.15, 6.5.18)
Impact:
Successful exploitation may allow attackers to take over affected Zoom account.
Resolution:
Upgrade affected software to the latest supported versions.
Reference:
UIT Information Security
