Description

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

Severity (CVSS)

Base score7.8
SeverityHigh
VersionCVSS 3.1
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Provided byCNA

Weaknesses

  • CWE-20 — CWE-20 Improper input validation

Affected products

VendorProductVersions
Zoom CommunicationsZoom Workplace VDI Plugin0 to <6.6.14

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 17 Jul 2026 07:01 UTC.