
[CIVN-2026-0374] Multiple Vulnerabilities in Zoom Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Zoom Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Zoom Rooms for Windows before version 7.1.0
Zoom Workplace for Windows before version 7.0.5
Zoom Workplace VDI Client for Windows before versions 6.5.18, 6.6.15 and 7.0.10 in their respective branch
Zoom Workplace VDI plugin for Windows before versions 6.5.17 and 6.6.14 in their respective branch
Zoom Remote Control for Zoom Contact Center for Windows before version 7.0.0
Overview
Multiple vulnerabilities have been reported in Zoom products that could be exploited by an attacker to achieve privilege escalation and account takeover via network access.
Target Audience:
All end-user organisations and individuals using the affected versions of Zoom applications.
Risk Assessment:
Critical risk of unauthorized access, privilege escalation, and system compromise.
Impact Assessment:
Potential for bypassing security restrictions, privilege escalation, and account takeover.
Description
Zoom is a communications platform that provides video conferencing, team chat, phone services, whiteboard, mail, calendar, and other collaboration services for individuals and organisations.
Multiple vulnerabilities exist in Zoom products due to improper input validation, race conditions (time-of-check to time-of-use), and improper privilege management.
Successful exploitation of these vulnerabilities could allow an attacker to gain elevated privileges and account takeover via network access on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendors given below:
https://www.zoom.com/en/trust/security-bulletin/zsb-26011/
https://www.zoom.com/en/trust/security-bulletin/zsb-26012/
https://www.zoom.com/en/trust/security-bulletin/zsb-26013/
https://www.zoom.com/en/trust/security-bulletin/zsb-26014/
Vendor Information
Zoom
https://www.zoom.com/en/trust/security-bulletin/
References
Zoom
https://www.zoom.com/en/trust/security-bulletin/zsb-26011/
https://www.zoom.com/en/trust/security-bulletin/zsb-26012/
https://www.zoom.com/en/trust/security-bulletin/zsb-26013/
https://www.zoom.com/en/trust/security-bulletin/zsb-26014/
CVE Name
CVE-2026-53409
CVE-2026-53410
CVE-2026-53411
CVE-2026-53412
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpiKLkACgkQ3jCgcSdc
ys/SNg//bnyqjQnIlbgDolWd0OupN0DUx+ZGL54AStRZdMfU2JUgljixKOQZdc9+
SCMj3jOEjoyqCdcSj3J77n1sVcb56dcseKK3T2Ax1eBeXKhdDdeYsklHi16pfBVQ
mgJy4Qmwrei5if/s5G1YG6GA2zXxnLx3wGYbqVimINklroTCzHbYdIs1jTHxtVDP
tur3TkiVh9pNRBAcH9pvHTZwZS/EBDoaBQ6EfuOT09ewV7StMGRCFe1v9kNiFIyH
HF25AsM7Q6y1IbxNOyl1kwLdQOTYCL0O5ibOqdrvI9A2Au6dZgrbn6OzzpJbEiAO
wsgyWHoKsbQ8Q3FZqM6+Vetp+QGQEs5AOyVe8vRknao9FGBnEcxnlItF+s9dtizO
EivT2U+KML2rkokjpXcKOoFpNXBgsolHTSaeUc0/ku/fVCNEtyOgBrs5OhkNyzJU
pXUwLwBCxs2C2iQzuxlkKAuExa23FujFXWiYGLmPEBHckVN7ulkp9ob+/xfe9oU/
9rJyHeHApX7Z2DUnBPnmmhQ+Pu2u/83ErKDDuTFNGLFVPn3Lfk5xC0VG/DK762Nt
YcPrrAlkMnjbuhCr0xGB8od7VkBzM/pJoeepc2Ym7qZKH57KrYmO1RL9u/i+0/bh
Fd70IfWMm+kqXFv+DNA6yeuSnkug1p7G3cd7V/05x8VTuXE8jQQ=
=1Pri
—–END PGP SIGNATURE—–


