Impact
A missing bounds check in the annotator function of Zoom Clients permits a buffer overwrite, which can lead to arbitrary code execution when a meeting participant sends malicious content. The flaw is a classic memory corruption vulnerability (CWE‑787) that allows an attacker to control execution flow by overflowing a heap buffer during annotation processing. Consequently, an adversary can take control of the target participant’s machine, compromising confidentiality, integrity, and availability of that user’s system.
Affected Systems
Zoom Communications’ Zoom Clients are affected. No specific version information is provided in the advisory, so all installed Zoom Client releases should be reviewed for the patch disclosed in the Zoom security bulletin.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity impact. The EPSS score of 6% indicates a moderate probability of exploitation, suggesting a higher likelihood the vulnerability may be actively used. The vulnerability is not listed in the CISA KEV catalog, but it can be triggered through network access within a Zoom meeting. An attacker who becomes a meeting participant can harvest the correct payload via the annotator interface to execute code remotely on other participants.
OpenCVE Enrichment