
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-53410 is a Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in the installation and uninstallation process of certain Zoom Clients for Windows that could allow an authenticated local user to escalate privileges. It was published by Zoom on July 14, 2026, and added to the NVD and GitHub Advisory Database on July 16, 2026. The vulnerability carries a CVSS v3.1 base score of 7.0 (High) (Zoom Advisory, GitHub Advisory).
The vulnerability is classified as CWE-367 (Time-of-Check Time-of-Use Race Condition), where the Zoom Client installer/uninstaller checks the state of a resource and then uses it, but the resource's state can be altered between the check and the use — a window an attacker can exploit. This is consistent with CAPEC-27 (Leveraging Race Conditions via Symbolic Links) and CAPEC-29 (Leveraging TOCTOU Race Conditions), suggesting the attack may involve manipulating file system objects such as symbolic links during the installation or uninstallation window (Zoom Advisory, GitHub Advisory). Exploitation requires local authenticated access and high attack complexity, as the attacker must win a precise timing race during the install/uninstall process (GitHub Advisory).
Successful exploitation allows an authenticated local user to escalate privileges on the affected Windows system, potentially gaining elevated or SYSTEM-level access. The NVD SSVC assessment rates the technical impact as "total," meaning confidentiality, integrity, and availability are all fully compromised upon successful exploitation. This could enable an attacker to install malware, access sensitive data, or persist on the system with elevated rights, though lateral movement would require additional steps beyond the initial privilege escalation (Zoom Advisory, GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure (Zoom Advisory). The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not automatable, reflecting the high attack complexity required to win the race condition. The EPSS score is approximately 0.094%, placing it in the 1st percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
C:\Windows\System32) by the Zoom installer process.ZoomInstaller.exe or similar) spawning unexpected child processes or writing to locations outside the expected installation path.HKLM\SOFTWARE or HKLM\SYSTEM made by the Zoom installer process outside of normal installation paths.Zoom has released a patch addressing this vulnerability; users should update to the latest Zoom Client version available at https://zoom.us/download (Zoom Advisory). As a workaround, organizations should restrict installation and uninstallation operations to minimize the timing window for race condition exploitation, and limit who can perform Zoom installs on endpoints. Applying the patch is the recommended and definitive remediation.
The vulnerability received notable media coverage, with outlets including BleepingComputer, The Hacker News, Security Affairs, TechRadar, Heise, and eSecurity Planet reporting on the broader Zoom security bulletin that included this CVE alongside the more critical CVE-2026-53412 (a critical account takeover flaw) (BleepingComputer, The Hacker News, Security Affairs). Much of the community attention was focused on the more severe CVE-2026-53412, with CVE-2026-53410 receiving secondary coverage as part of the same patch batch. The University of Toronto issued an advisory urging users to update their Zoom clients promptly (U of T Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."