
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-53410 is a Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in the installation and uninstallation process of certain Zoom Clients for Windows. It allows an authenticated local user to escalate privileges by exploiting a timing window during package installation or removal operations. The vulnerability was disclosed by Zoom on July 14, 2026, and published to the NVD on July 16, 2026. It carries a CVSS v3.1 base score of 7.0 (High) (Zoom Advisory, Github Advisory).
The vulnerability is classified as CWE-367 (Time-of-Check Time-of-Use Race Condition), where the Zoom installer or uninstaller checks the state of a resource and then uses it, but the resource's state can be altered by a local attacker in the window between the check and the use. This is consistent with CAPEC-27 (Leveraging Race Conditions via Symbolic Links) and CAPEC-29 (Leveraging TOCTOU Race Conditions), suggesting the attack may involve symlink substitution or similar file-system manipulation during the install/uninstall process (Zoom Advisory, Github Advisory). Exploitation requires local access with low privileges and has high attack complexity due to the precise timing required. No public proof-of-concept code has been identified.
Successful exploitation grants an authenticated local attacker elevated privileges on the affected Windows system, with high impact to confidentiality, integrity, and availability. An attacker who wins the race condition could gain SYSTEM-level or administrator-level access, enabling them to install malware, access sensitive data, modify system configurations, or facilitate lateral movement within a network. The scope is limited to the local system, but privilege escalation can serve as a critical stepping stone in a broader attack chain (Zoom Advisory, Github Advisory).
%TEMP%, %ProgramFiles%\Zoom, or %LocalAppData%\Zoom); new or modified files in system directories (e.g., C:\Windows\System32) with timestamps coinciding with Zoom install/uninstall events.ZoomInstaller.exe) or uninstaller with elevated privileges; processes such as cmd.exe, powershell.exe, or other shells launched as SYSTEM during or immediately after a Zoom install/uninstall operation.%TEMP%\MSI*.log) showing unexpected file operations or errors during installation.Zoom has released a patch addressing this vulnerability; users should update to the latest version of Zoom Client for Windows available at https://zoom.us/download (Zoom Advisory). As a workaround, organizations should restrict installation and uninstallation operations to minimize the timing window for race condition exploitation — for example, by limiting who can initiate Zoom installs or by using centralized software deployment tools. Applying the principle of least privilege and monitoring for unusual file system activity during software installation events is also recommended.
The vulnerability received broad media coverage, with outlets including BleepingComputer, The Hacker News, Security Affairs, TechRadar, Heise, and eSecurity Planet reporting on the broader Zoom July 2026 security bulletin, which also included the more critical CVE-2026-53412 (account takeover). Much of the media attention was focused on CVE-2026-53412 rather than CVE-2026-53410 specifically, as the account takeover flaw carried a higher severity rating. Security researchers on Mastodon and threat intelligence platforms noted the patch availability and low exploitation risk for CVE-2026-53410 given its local-only attack vector and high complexity (BleepingComputer, The Hacker News, Security Affairs).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."