Description
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
Published: 2026-07-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A time‑of‑check to time‑of‑use race condition in the installation and uninstallation process of the Zoom Workplace VDI Plugin for Windows allows an authenticated local user to elevate privileges and potentially gain system‑level access. The flaw arises from improper input validation, classified as CWE‑20, and could compromise confidentiality, integrity, and availability by granting escalation of rights within the host system.

Affected Systems

The affected product is Zoom Communications' Zoom Workplace VDI Plugin for Windows. Specific version information is not provided, but the vulnerability applies to the installation and uninstallation process of the Zoom Workplace VDI Plugin on Windows operating systems. No further version data is available.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a low current chance of exploitation. The flaw requires a local authenticated user to execute the exploit, making it not remotely exploitable but still significant for any user who has installer privileges. Although not listed in the CISA KEV catalog, the privilege escalation potential warrants timely patching.

Generated by OpenCVE AI on July 31, 2026 at 01:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Zoom Workplace VDI Plugin update or patch from Zoom.
  • Restrict installation and uninstallation privileges to administrators only to limit local user access.
  • If an update is not available, disable the installation/uninstallation feature or apply application controls to block the component from executing during these operations.

Generated by OpenCVE AI on July 31, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Zoom Communications
Zoom Communications zoom Workplace
Vendors & Products Zoom Communications
Zoom Communications zoom Workplace

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
Title Zoom Workplace VDI Plugin for Windows - Improper Input Validation
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zoom Communications Zoom Workplace
cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published:

Updated: 2026-07-17T13:19:18.986Z

Reserved: 2026-06-09T10:18:05.660Z

Link: CVE-2026-53411

cve-icon Vulnrichment

Updated: 2026-07-17T13:19:15.282Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation