Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN769 _____________________________________________________________________ DATE : 20/07/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Zoom Workplace for Windows versions prior to 7.0.5, Zoom Workplace VDI Client for Windows, Zoom Workplace VDI plugin for Windows versions prior to 7.0.10, 6.6.15, 6.5.18, Zoom Rooms for Windows versions prior to 7.1.0, Remote Control for Zoom Contact Center for Windows versions prior to 7.0.0. ===================================================================== https://www.zoom.com/en/trust/security-bulletin/zsb-26014/ https://www.zoom.com/en/trust/security-bulletin/zsb-26012/ https://www.zoom.com/en/trust/security-bulletin/zsb-26011/ https://www.zoom.com/en/trust/security-bulletin/zsb-26013/ _____________________________________________________________________ Zoom Workplace for Windows - Improper Input Validation Bulletin: ZSB-26014 CVEID: CVE-2026-53412 CVSS Severity: Critical CVSS Score: 9,8 CVSS Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Description: Improper Input Validation in Zoom Desktop Client for Windows and Zoom VDI Client for Windows may allow an unauthenticated user to conduct an account takeover via network access. Users can help keep themselves secure by applying the latest updates available at https://zoom.us/download. Affected Products: Zoom Workplace for Windows before version 7.0.0 Zoom Workplace VDI Client for Windows before version 7.0.10 and 6.6.15 and 6.5.18 in their respective branches Source: Reported by Zoom Offensive Security Revision Date Description 1.1 07/15/2026 Removed Meeting SDK for Windows as an affected product. 1.0 07/14/2026 Initial publication. _____________________________________________________________________ Zoom Clients for Windows - Race Condition Bulletin: ZSB-26012 CVEID: CVE-2026-53410 CVSS Severity: High CVSS Score: 7 CVSS Vector String: https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Description: A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges. Users can help keep themselves secure by applying the latest updates available at https://zoom.us/download. Affected Products: Zoom Workplace for Windows before version 7.0.5 Zoom Workplace VDI Client for Windows before 6.5.17 and 6.6.14 in their respective branch Zoom Workplace VDI plugin for Windows before 6.5.17 and 6.6.14 in their respective branch Zoom Rooms for Windows before 7.0.5 Remote Control for Zoom Contact Center for Windows before version 7.0.0 Source: Reported by sim0nsecurity Revision Date Description 1.0 07/14/2026 Initial publication. _____________________________________________________________________ Zoom Rooms for Windows - Improper Privilege Management Bulletin: ZSB-26011 CVEID: CVE-2026-53409 CVSS Severity: High CVSS Score: 7,8 CVSS Vector String: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Description: Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access. Users can help keep themselves secure by applying the latest updates available at https://zoom.us/download. Affected Products: Zoom Rooms for Windows before version 7.1.0 Source: Reported by sim0nsecurity Revision Date Description 1.0 07/14/2026 Initial publication. _____________________________________________________________________ Zoom Workplace VDI Plugin for Windows - Improper Input Validation Bulletin: ZSB-26013 CVEID: CVE-2026-53411 CVSS Severity: High CVSS Score: 7,8 CVSS Vector String: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Description: Improper Input Validation in the Zoom Workplace VDI Plugin for Windows before version 6.6.14 may allow an authenticated user to conduct an escalation of privilege via local access. Users can help keep themselves secure by applying the latest updates available at https://zoom.us/download. Affected Products: Zoom Workplace VDI Plugin for Windows versions prior to 6.6.14 Source: Reported by sim0nsecurity Revision Date Description 1.0 07/14/2026 Initial publication. ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================