CVE Tools

В Zoom исправили уязвимость, позволявшую выполнять произвольный код

Хакер (xakep.ru)By Мария Нефёдова

PatchZoom WorkplaceZoom Meeting SDK

Our summary

A Security researchers disclosed a cluster of vulnerabilities dubbed "Zoomsday" that allowed remote attackers to execute arbitrary code on systems running Zoom Workplace and the Meeting SDK. The flaws, primarily located in the screen sharing annotation handler, enabled zero-click attacks against participants receiving shared content across Windows, macOS, Linux, iOS, and Android.

The most severe issue, CVE-2026-53413 (CVSS 8.3), involved buffer boundary miscalculations leading to memory corruption, while CVE-2026-53414 (CVSS 6.5) facilitated out-of-bounds reads potentially useful for bypassing ASLR. A third defect, CVE-2026-53415 (CVSS 8.3), was identified as a use-after-free error. Although Zoom officially rated the aggregate risk lower by citing user interaction requirements, the researchers assert these bugs constitute a critical zero-click threat vector.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store