Zoom patches critical account takeover vulnerability affecting Windows clients (heise.de)
0xBASE INTEL BRIEF
- CVE-2026-53412: Critical remote account takeover with no authentication required.
- Three high-severity bugs: local privilege escalation via input validation, improper privilege management, and TOCTOU race condition.
- All patches available; Zoom recommends immediate updates for Windows clients.
"Zoom has fixed several security flaws, including a critical (CVSS 9.8) remote account takeover vulnerability affecting Windows clients. Three other high-severity bugs could allow local privilege escalation. Updates are available via the Zoom download portal."
no comments yet.