Zoom Patches Zero-Click Code Execution Vulnerability

https://www.securityweek.com/wp-content/uploads/2023/06/Zoom-Data-Security-Privacy.jpg

Zoom on Tuesday announced rolling out patches for four vulnerabilities in its products, including a severe flaw that allowed zero-click remote code execution (RCE).

Impacting Zoom’s clients on all supported platforms, three of the security defects were discovered in the annotator function, which uses a proprietary protocol.

The most severe of the three bugs is CVE-2026-53413, a memory corruption issue that allowed a meeting participant to execute code on another participant’s machine, says A Security, which found the bug and named it Zoomsday.

The security firm exploited “the fact that every Zoom client automatically parses whatever it receives, sending a specially crafted message to corrupt the receiving client’s memory and run code on it.”

An attacker could leverage the fact that the proprietary protocol used by the annotator opens a direct channel between a viewer and a sharer, thereby targeting each meeting participant individually.

“The exploit enables attackers to...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more