Threat Advisory

Zoom Annotation Flaw Lets Attackers Execute Code on Another Participant’s Machine

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Zoom's products, including a severe zero-click remote code execution (RCE) vulnerability that could allow an attacker to execute code on another participant's machine. The vulnerabilities impact Zoom's clients on all supported platforms and were discovered in the annotator function, which uses a proprietary protocol. Affected version ranges include Workplace versions 7.1.5 and 7.0.6, Rooms version 7.1.5, Meeting SDK version 7.1.5 for all supported platforms, Workplace VDI Client for Windows versions 7.0.11 and 6.6.16, and Workplace VDI Plugins versions 7.0.11 and 6.6.15.

CVE-2026-53413: A memory corruption issue in the annotator function allows a meeting participant to execute code on another participant's machine by sending a specially crafted message that corrupts the receiving client's memory and runs code on it.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Zoom's products, including a severe zero-click remote code execution (RCE) vulnerability that could allow an attacker to execute code on another participant's machine. The vulnerabilities impact Zoom's clients on all supported platforms and were discovered in the annotator function, which uses a proprietary protocol. Affected version ranges include Workplace versions 7.1.5 and 7.0.6, Rooms version 7.1.5, Meeting SDK version 7.1.5 for all supported platforms, Workplace VDI Client for Windows versions 7.0.11 and 6.6.16, and Workplace VDI Plugins versions 7.0.11 and 6.6.15.

CVE-2026-53413: A memory corruption issue in the annotator function allows a meeting participant to execute code on another participant's machine by sending a specially crafted message that corrupts the receiving client's memory and runs code on it.[emaillocker id="1283"]

CVE-2026-53414: A missing bound check in the text annotator allows an attacker to send crafted messages that write attacker-supplied code past the intended buffer, leading to RCE and targeting any meeting participant with a denial-of-service (DoS) attack.

CVE-2026-53415: A use-after-free flaw in the annotator function allows an attacker to target any meeting participant with a DoS attack by exploiting the fact that every Zoom client automatically parses whatever it receives.

CVE-2026-53416: A path traversal flaw in one of Zoom's products leads to information disclosure, allowing an attacker to access sensitive data. These vulnerabilities collectively present a significant risk to Zoom users, particularly those who participate in meetings or use Zoom's annotation feature. These vulnerabilities collectively present a significant risk to Zoom users, particularly those who participate in meetings or use Zoom's annotation feature.

These vulnerabilities collectively present a significant risk to Zoom users, particularly those who participate in meetings or use Zoom's annotation feature.

RECOMMENDATION:

We recommend you to update Zoom to version 7.1.5, 7.0.6, 7.0.11, 6.6.16, or 6.6.15.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu