91亚色

Skip to main content Skip to local navigation

Zoom Workplace for Windows - Improper Input Validation (CVE-2026-53412)

A recently disclosed vulnerability (CVE-2026-53412) that affects Zoom Workplace for Windows and Zoom Workplace VDI Client for Windows and may allow an unauthenticated remote attacker to take over a user account via network access.

Severity level:
CVSS Score: 9.8/Critical.

Description:

CVE-2026-53412 is a critical vulnerability caused by improper input validation in Zoom Workplace for Windows and Zoom Workplace VDI Client for Windows. An unauthenticated attacker can exploit the flaw remotely over a network to perform an account takeover.

Affected Versions:

  • Zoom Workplace for Windows before 7.0.0.
  • Zoom Workspace VDI client for Windows before (7.0.10, 6.6.15, 6.5.18)

Impact:

Successful exploitation may allow attackers to take over affected Zoom account.

Resolution:

Upgrade affected software to the latest supported versions.

Reference:

UIT Information Security