Impact
The vulnerability is a use‑after‑free bug in the Zoom Clients’ annotator function that can be triggered by a meeting participant. Exploitation would allow the attacker to execute arbitrary code on another participant’s device, potentially leading to full system compromise, data exfiltration, or further network infiltration. The flaw stems from an improper free of memory that is later accessed, matching CWE‑416.
Affected Systems
The affected product is the Zoom Communications Zoom Clients. No specific version range is listed, indicating that all client builds released before a vendor‑supplied fix may be impacted. The vulnerability applies to Windows, macOS, iOS, and Android clients that support the annotator feature.
Risk and Exploitability
The CVSS score of 8.3 rates this as a high‑severity issue, yet the EPSS score is less than 1%, suggesting that exploitation in the wild is currently low but possible. The flaw is not yet in the CISA KEV catalogue. An attacker would need to be a meeting participant with network access to the vulnerable client and would exploit the annotator function to trigger the use‑after‑free and gain code execution.
OpenCVE Enrichment