Description
Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.
Published: 2026-07-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in Zoom Rooms for Windows prior to version 7.1.0 and is caused by improper privilege management. An authenticated local user can exploit this flaw to elevate their privileges on the host system. This allows the attacker to gain higher‑level access than intended, enabling potential execution of arbitrary code with elevated authority. The weakness is categorized as CWE‑20, reflecting inadequate input or state validation during privilege handling.

Affected Systems

Zoom Communications’ Zoom Rooms application running on Windows machines with versions earlier than 7.1.0 are impacted. Users who can log into Zoom Rooms with credentials that provide local access are at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity condition for privilege escalation. The EPSS score of less than 1% shows that, at this time, the exploitation probability in the wild is low. The flaw is not listed in the CISA KEV catalog, and the attack vector is local, requiring authenticated access to Zoom Rooms on the targeted machine. Inherited from the data, the vulnerability would likely be leveraged by insiders or attackers who have compromised a user credential and then attempt to elevate rights on the same host.

Generated by OpenCVE AI on August 1, 2026 at 08:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Zoom Rooms to version 7.1.0 or later, which contains the fix for the privilege escalation issue.
  • If an immediate upgrade is not feasible, restrict the rights of local Zoom Rooms users by applying the least‑privilege principle; for example, disable administrative capabilities or enforce a separate, lower‑privileged account for regular operation.
  • Reduce the attack surface by disabling or removing any unused Zoom Rooms services or components that run under the local user account.

Generated by OpenCVE AI on August 1, 2026 at 08:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Improper Privilege Management Enables Local Privilege Escalation in Zoom Rooms for Windows

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Zoom Communications
Zoom Communications zoom Rooms
Vendors & Products Zoom Communications
Zoom Communications zoom Rooms

Tue, 28 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Improper Privilege Management Enables Local Privilege Escalation in Zoom Rooms for Windows

Sat, 25 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Privilege Management in Zoom Rooms for Windows

Wed, 22 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Privilege Management in Zoom Rooms for Windows

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zoom Communications Zoom Rooms
cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published:

Updated: 2026-07-17T13:20:11.431Z

Reserved: 2026-06-09T10:12:34.854Z

Link: CVE-2026-53409

cve-icon Vulnrichment

Updated: 2026-07-17T13:20:08.012Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T08:45:02Z

Weaknesses
  • CWE-20

    Improper Input Validation