В Zoom для Windows исправили критическую уязвимость
PatchZoom WorkplaceVDI ClientOur summary
Zoom has issued updates for its Windows-based applications and software development kits (SDKs) to address a critical vulnerability identified as CVE-2026-53412. This flaw could allow an unauthenticated attacker to remotely take over a victim's account, earning it a high CVSS score of 9.8. The issue was discovered internally by Zoom engineers and stems from improper input validation affecting Zoom Workplace, VDI Client, and Meeting SDK on Windows platforms. Additionally, the update resolves three other vulnerabilities rated between 7.0 and 7.8 on the CVSS scale, all related to privilege escalation risks.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.