Description
Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.
Published: 2026-07-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Zoom Communications
Zoom Communications zoom Rooms
Vendors & Products Zoom Communications
Zoom Communications zoom Rooms

Tue, 28 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Improper Privilege Management Enables Local Privilege Escalation in Zoom Rooms for Windows

Sat, 25 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Privilege Management in Zoom Rooms for Windows

Wed, 22 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Privilege Management in Zoom Rooms for Windows

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zoom Communications Zoom Rooms
cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published:

Updated: 2026-07-17T13:20:11.431Z

Reserved: 2026-06-09T10:12:34.854Z

Link: CVE-2026-53409

cve-icon Vulnrichment

Updated: 2026-07-17T13:20:08.012Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T20:27:55Z

Weaknesses
  • CWE-20

    Improper Input Validation