Junglewise Threat Intelligence

CVE-2026-53414: Zoom Clients buffer over-read in annotator function

CVE-2026-53414 · Severity: medium · CVSS 6.5 · Published 2026-08-11

Technologies: Zoom Workplace, Zoom Meeting SDK, Zoom Workplace VDI Client for Windows, Zoom Rooms, Zoom Video SDK. Vendors: Zoom.

Executive brief

Zoom Clients contain a missing bounds check in the annotation tool that can be exploited by a meeting participant to crash another participant's application, causing a temporary denial of service. An attacker needs only to participate in a meeting and send a specially crafted annotation to trigger the issue, requiring no special permissions or credentials.

Technical details

A missing bounds check in the annotator function allows a buffer over-read vulnerability in Zoom Clients. The vulnerability is triggered via network access by a malicious meeting participant who can send a crafted annotation payload to another participant. The attack requires user interaction (victim must be in an active meeting with the attacker) but no authentication beyond normal meeting participation. A successful exploit results in a denial of service condition affecting the targeted participant's client. Patches are available in Zoom Workplace 7.1.0 / 7.0.6, Zoom Rooms 7.1.0, Zoom Meeting SDK 7.1.0, Zoom Video SDK 2.6.0, and Zoom Workplace VDI Client 7.0.11 / 6.6.16.

Affected products

  • Zoom Zoom Workplace before 7.1.0 and 7.0.6 (branch-dependent)
  • Zoom Zoom Workplace VDI Client for Windows before 7.0.11 and 6.6.16 (branch-dependent)
  • Zoom Zoom Rooms before 7.1.0
  • Zoom Zoom Meeting SDK before 7.1.0
  • Zoom Zoom Video SDK before 2.6.0

Timeline

  • 2026-08-11: disclosed: Initial publication of ZSB-26016
  • 2026-08-14: other: Revised bulletin adding Zoom Video SDK and correcting version information

References

Related threats