Description
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
Published: 2026-07-16
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A time‑of‑check to time‑of‑use race condition exists in the installation and uninstallation processes of Zoom Clients for Windows. An authenticated local user can trigger the condition and potentially gain higher privileges on the infected host.

Affected Systems

Zoom Communications Zoom Clients running on Windows are potentially affected. The issue is tied to the generic installation and uninstallation paths used by the client, and no specific version numbers are provided, so all deployed Windows Zoom clients should be considered vulnerable until patched.

Risk and Exploitability

The CVSS score of 7 indicates high severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an authenticated user must initiate a concurrent install or uninstall operation. While exploitation would remain limited to the authenticated user’s privileges, the potential for privilege escalation warrants prompt remediation.

Generated by OpenCVE AI on August 1, 2026 at 08:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Zoom client update that includes a fix for the race condition.
  • Restrict installation and uninstallation rights to administrative accounts only, preventing ordinary users from executing these actions.
  • Enforce least‑privilege policies for local users, removing unnecessary install privileges and ensuring only trusted accounts can modify system software.

Generated by OpenCVE AI on August 1, 2026 at 08:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Zoom Communications
Zoom Communications zoom Clients
Vendors & Products Zoom Communications
Zoom Communications zoom Clients

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
Title Zoom Clients for Windows - Race Condition
Weaknesses CWE-367
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zoom Communications Zoom Clients
cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published:

Updated: 2026-07-17T13:19:48.397Z

Reserved: 2026-06-09T10:12:34.854Z

Link: CVE-2026-53410

cve-icon Vulnrichment

Updated: 2026-07-17T13:19:43.722Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T08:45:02Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition