Junglewise Threat Intelligence

CVE-2026-53413: Zoom Clients buffer overflow in annotator function

CVE-2026-53413 · Severity: high · CVSS 8.3 · Published 2026-08-11

Technologies: Zoom Workplace, Zoom Meeting SDK, Zoom Rooms, Zoom Workplace VDI Client, Zoom Video SDK. Vendors: Zoom.

Executive brief

Zoom meeting clients contain a missing bounds check in the annotation feature that allows a malicious meeting participant to write data beyond allocated memory boundaries. This vulnerability could allow an attacker to execute arbitrary code on another participant's computer during a meeting, compromising confidentiality, integrity, and availability of their system.

Technical details

A missing bounds check in the annotator function of Zoom Clients allows buffer over-write, enabling remote code execution. The vulnerability requires network access and user interaction (attending a meeting with a malicious participant), but does not require authentication beyond joining the meeting. An attacker can exploit this by sending specially crafted annotation data to trigger the buffer overflow and achieve arbitrary code execution on the victim's machine. Patches are available in Zoom Workplace 7.1.0/7.0.6, Zoom Workplace VDI Client 7.0.11/6.6.16, Zoom Rooms 7.1.0, Zoom Meeting SDK 7.1.0, and Zoom Video SDK 2.6.0.

Affected products

  • Zoom Zoom Workplace all supported platforms before version 7.1.0 and 7.0.6 in their respective branches
  • Zoom Zoom Workplace VDI Client Windows before versions 7.0.11 and 6.6.16 in their respective branches
  • Zoom Zoom Rooms all supported platforms before version 7.1.0
  • Zoom Zoom Meeting SDK all supported platforms before version 7.1.0
  • Zoom Zoom Video SDK all supported platforms before version 2.6.0

Timeline

  • 2026-08-11: disclosed: CVE-2026-53413 published
  • 2026-08-14: other: Zoom Security Bulletin ZSB-26015 revised to add Zoom Video SDK to affected products

References

Related threats