Executive brief
Zoom's meeting clients (desktop and VDI applications) contain a memory safety vulnerability in their annotation feature that could allow an attacker to execute malicious code on a participant's computer. A malicious meeting participant could exploit this to take over another user's system, access sensitive data, or install persistent malware—all without additional user action beyond normal meeting participation.
Technical details
A use-after-free vulnerability exists in the annotator function of Zoom Clients, where freed memory is accessed after deallocation, leading to potential code execution. The vulnerability requires network access and user interaction (the target must be in an active meeting), but no special privileges are needed. An attacker participating in the same meeting can trigger the vulnerability to achieve remote code execution with the privileges of the Zoom process. Patches are available: Zoom Workplace updated to 7.1.5 or 7.0.6, VDI Client to 7.0.11 or 6.6.16, Zoom Rooms to 7.1.5, Meeting SDK to 7.1.5, and Video SDK to 2.6.5.
Affected products
- Zoom Workplace before 7.1.5 and 7.0.6
- Zoom Workplace VDI Client for Windows before 7.0.11 and 6.6.16
- Zoom Rooms before 7.1.5
- Zoom Meeting SDK before 7.1.5
- Zoom Video SDK before 2.6.5
Timeline
- 2026-08-11: disclosed: CVE-2026-53415 published by Zoom
- 2026-08-14: other: Zoom Video SDK added to affected products list (revision 1.1)