Impact
The vulnerability is a missing bounds check in the Zoom Clients’ annotator function, enabling a buffer over‑read. This can lead to a denial of service against another participant when the attacker abuses network access during a meeting. The weakness is classified as CWE‑126: Buffer Over‑read.
Affected Systems
Zoom Communications Zoom Clients. The CVE refers to all Zoom Clients but does not list specific versions; the vendor product is Zoom Communications:Zoom Clients.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation, and it is not flagged in the CISA KEV catalog. The attack vector is inferred to be remote via network access during a meeting where the annotator function can be invoked by a participant. This requires the victim to be in the same meeting as the attacker.
OpenCVE Enrichment