Vulnerability Intelligence Report
Zoom Clients for Windows - Race Condition
CVE-2026-53410
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
No Active Exploit Signals
CVSS Base Score
7.0
HIGH
Exploitability:1.1
Impact Score:5.9
EPSS Probability:0.09%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-367 ↗CWE-367 Time-of-check time-of-use (TOCTOU) race condition
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Zoom Communications | Zoom Clients | see references (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.093%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Zoom Communications, Inc. · Vendor · USA |
| Reserved | 2026-06-09T10:12:34 |
| Published | 2026-07-16T21:11:44 |
| Patch Date | 2026-07-14 |
| Last Updated | 2026-07-17T13:19:48 |
Community Chatter & Buzz