Out-of-Bounds Write in Zoom Clients Enables Participant-to-Participant RCE
CVSS 3.1
8.3high
EPSS
6%p92
Published
()
Modified
AI analysis
Zoom has fixed an out-of-bounds write (CWE-787) in the annotator function of its client applications, tracked as CVE-2026-53413. A meeting participant can trigger the missing bounds check remotely through the annotation feature, causing a buffer over-write in another attendee's client; per the CVSS vector, user interaction and high attack complexity are required. Successful exploitation may allow the attacker to execute code on the victim's machine with that user's privileges, effectively hijacking another participant's client from within the same meeting. Anyone running a vulnerable Zoom Client (the platform's desktop and mobile apps, used by an extremely large user base) is potentially affected until patched. There is no public proof-of-concept, the flaw is not yet in CISA's KEV catalog, and no exploitation in the wild is known, though an EPSS of 5.6% (92nd percentile) indicates meaningful exploitation potential.
What to do: Update Zoom Clients to the patched release identified in Zoom's advisory for CVE-2026-53413 and verify installed client versions across managed endpoints. Until patched, limit annotation privileges in meetings to trusted participants and treat meetings with untrusted external attendees as elevated risk. Monitor Zoom's advisory for exact affected/fixed version ranges, since no public PoC exists but EPSS suggests elevated exploitation likelihood.
Affected
Zoom Clients (client applications)
—
Estimated exposure
masswell over 1,000,000 users — plausibly tens to hundreds of millions of meeting participants running unpatched Zoom Clients — Zoom is one of the largest video-conferencing platforms, with hundreds of millions of daily meeting participants, so essentially the entire installed base of not-yet-updated Zoom Clients is potentially exposed.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.
A Security researchers disclosed three Zoom annotation flaws enabling zero-click client hijacking; Zoom shipped fixes in June and July with no exploitation reported.
Researchers at A Security found three flaws in Zoom's annotation feature: CVE-2026-53413 (CVSS 8.3, buffer over-write), CVE-2026-53414 (CVSS 6.5, buffer over-read), and CVE-2026-53415 (CVSS 8.3, use-after-free). A crafted drawing object sent over the wrong message channel can overwrite adjacent memory and hijack another attendee's client with no user interaction. Fixes shipped in Zoom Workplace 7.1.5/7.0.6, VDI Client 7.0.11/6.6.16, and Zoom Rooms/Meeting SDK 7.1.0+ during June and July. No exploitation has been reported and the flaws are absent from CISA's Known Exploited Vulnerabilities catalog.
Zoom patched CVE-2026-53413, a zero-click annotation flaw dubbed "Zoomsday" allowing remote code execution on meeting participants' devices across all platforms.
Zoom patched four vulnerabilities, including CVE-2026-53413, a stack buffer overflow in CAnnoFormatBlock::Deserialize in the annotation protocol that allows zero-click remote code execution on another participant's device. A Security also found CVE-2026-53414, a buffer overread enabling denial-of-service crashes, and CVE-2026-53415, a use-after-free Zoom had already discovered internally. Updates shipped for Workplace 7.1.5 and 7.0.6, Rooms 7.1.5, and Meeting SDK 7.1.5 across all supported platforms.