Zoom zero-click RCE flaws allow attackers to compromise meeting participants
Brief
Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them.
Three of the vulnerabilities affect all Zoom client applications for all platforms before versions 7.
- 5 and 7.
- 6, while the fourth impacts Zoom Workplace VDI Client for Windows and VDI Plugins on all supported platforms before versions 7.
- 11 and 6.
- 15. Products such as Zoom Rooms and Zoom Meeting SDK before versions 7.
- 0 are also affected.
The three client vulnerabilities are memory corruption issues in the text annotation function and were found by a researcher from A Security by using an AI agent.
