CYBERSECURITYTRACKER
TRACKING7,735 stories in this site build1,671 vulnerability news stories in this site build
Permanent story citation

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4249

As cited

Copy frozen at (site build).

vulnerabilities

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

Zoom's annotation feature contained a vulnerability that allowed meeting participants to execute arbitrary code on other attendees' computers during screen sharing sessions. The flaw required no user interaction from the victim, such as clicking or downloading, and left no visible indication of the attack.

Why it matters: Organizations using Zoom for video conferencing face remote code execution risk from any meeting participant; patch immediately if running affected versions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

Zoom's annotation feature contained a vulnerability that allowed meeting participants to execute arbitrary code on other attendees' computers during screen sharing sessions. The flaw required no user interaction from the victim, such as clicking or downloading, and left no visible indication of the attack.

Why it matters: Organizations using Zoom for video conferencing face remote code execution risk from any meeting participant; patch immediately if running affected versions.

VendorsZoom
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary