{"id":9099,"date":"2026-08-11T22:56:27","date_gmt":"2026-08-11T22:56:27","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9099"},"modified":"2026-08-11T22:56:27","modified_gmt":"2026-08-11T22:56:27","slug":"zoom-zero-click-rce-flaws-allow-attackers-to-compromise-meeting-participants","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9099","title":{"rendered":"Zoom zero-click RCE flaws allow attackers to compromise meeting participants"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them.<\/p>\n<p class=\"wp-block-paragraph\">Three of the vulnerabilities affect all Zoom client applications for all platforms before versions 7.1.5 and 7.0.6, while the fourth impacts Zoom Workplace VDI Client for Windows and VDI Plugins on all supported platforms before versions 7.0.11 and 6.6.15. Products such as Zoom Rooms and Zoom Meeting SDK before versions 7.1.0 are also affected.<\/p>\n<p class=\"wp-block-paragraph\">The three client vulnerabilities are memory corruption issues in the text annotation function and were found by a researcher from A Security by using an AI agent.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe entire operation, from finding the flaw to building a working exploit, was carried out by A [Security] using fewer than 20 prompts on publicly available AI models in under 24 hours,\u201d the company said in <a href=\"https:\/\/a.security\/blog\/asecurity-zoomsday\">its report<\/a>. \u201cThis class of capability would previously have only been available to nation-state threat actors, but the model requiring elite teams, months of effort, and weapons-grade budgets has collapsed. Today, a single researcher was able to develop a nation-state-level exploit in less than a day.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The researchers point out the massive potential blast radius of such an exploit, with Zoom being used by 70% of the Fortune 100 companies, most of the Fortune 500 ones, and federal agencies. In addition, this exploit doesn\u2019t need meeting participants to perform any type of action such as clicking or downloading anything. It all happens silently with no indication that the attacker has executed malicious code on their computer.<\/p>\n<h2 class=\"wp-block-heading\">How the vulnerability works<\/h2>\n<p class=\"wp-block-paragraph\">When a participant draws, writes, or highlights text on a shared screen or whiteboard in Zoom, their client doesn\u2019t send pixels. Instead, it builds a typed in-memory object that describes the action, then serializes this object into a byte stream and sends it to Zoom\u2019s Multimedia Router, which then forwards it to all meeting participants, whose client application deserializes the object.<\/p>\n<p class=\"wp-block-paragraph\">Data serialization and deserialization operations have been a big source of memory corruption vulnerabilities in applications because it\u2019s easy to get wrong and the input is attacker-controlled. Zoom allocates four fixed 128-byte buffers to write the deserialized annotation packets in, but the code only checks that the packets are non-zero, not their size.<\/p>\n<p class=\"wp-block-paragraph\">Therefore, if an attacker can generate a packet that fills and exceeds the four fixed buffers, they have a buffer overflow condition they can exploit to insert malicious code in the application\u2019s memory.<\/p>\n<p class=\"wp-block-paragraph\">The A Security researcher has identified a buffer overflow vulnerability, <a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/zsb-26015\/\">CVE-2026-53413<\/a>, and a use-after-free memory error, <a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/zsb-26017\/\">CVE-2026-53415<\/a>, both of which can read to remote code execution. A third flaw, <a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/zsb-26016\/\">CVE-2026-53414<\/a>, is a missing bounds check that can lead to a denial-of-service condition.<\/p>\n<p class=\"wp-block-paragraph\">Zoom also patched a path traversal flaw, <a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/zsb-26018\/\">CVE-2026-53416<\/a>, in the VDI client and plugins that could lead to information disclosure. Zoom VDI (Virtual Desktop Infrastructure) is a special version of the Zoom app that\u2019s designed to run on virtual desktops such as Citrix, VMware Horizon, and Azure Virtual Desktop.<\/p>\n<h2 class=\"wp-block-heading\">Mitigation<\/h2>\n<p class=\"wp-block-paragraph\">Aside from updating Zoom clients, organizations can disable the end-to-end encryption (E2EE) setting for their meetings. That\u2019s because Zoom has deployed server-side mitigation for this flaw that filters malicious annotation messages. When E2EE is enabled, the server only sees encrypted messages and cannot perform such filtering.<\/p>\n<p class=\"wp-block-paragraph\">Another mitigation is to set the per-platform minimum version for guests and staff in the meeting preferences and only allow patched clients to join meetings.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis exploit needed only presence in the meeting, so joining rules are access control: waiting rooms, passcodes, authenticated-users-only, no published personal meeting link,\u201d the researchers said. \u201cThen cut what nobody uses, because every optional feature is another parser. In Zoom, consider locking annotation, file transfer, whiteboarding, remote control and third-party apps, and limiting screen sharing to hosts.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them. Three of the vulnerabilities affect all Zoom client applications for all platforms before versions 7.1.5 and 7.0.6, while the [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9100,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9099","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9099"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9099"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9099\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9100"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9099"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9099"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9099"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}