CVE Tools

В Zoom для Windows исправили критическую уязвимость

Хакер (xakep.ru)By Мария Нефёдова

PatchZoom WorkplaceVDI Client

Our summary

Zoom has issued updates for its Windows-based applications and software development kits (SDKs) to address a critical vulnerability identified as CVE-2026-53412. This flaw could allow an unauthenticated attacker to remotely take over a victim's account, earning it a high CVSS score of 9.8. The issue was discovered internally by Zoom engineers and stems from improper input validation affecting Zoom Workplace, VDI Client, and Meeting SDK on Windows platforms. Additionally, the update resolves three other vulnerabilities rated between 7.0 and 7.8 on the CVSS scale, all related to privilege escalation risks.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store