CVE-2026-53413
CVSS 8.3 HIGH: missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting…
Vulnerabilità · 47 giorni fa
La funzione di annotazione di Zoom non è più solo un dettaglio della collaborazione: può diventare il punto da cui un partecipante compromette il client degli altri. Il NCSC olandese conferma che Zoom ha corretto quattro vulnerabilità in Zoom Client e Zoom VDI Client, tra cui CVE-2026-53413, una falla che può portare a esecuzione di codice sul dispositivo di un altro partecipante.
Le annotazioni passano come dati di collaborazione tra i client. Se il parser le accetta senza controlli adeguati, un messaggio costruito ad arte può mandare in crash il client ricevente o scrivere memoria in modo pericoloso. Il raggio d’azione non resta quindi sul solo host della riunione: riguarda ogni endpoint che partecipa alla sessione.
Per chi gestisce flotte desktop e piattaforme UC, il punto non è un exploit nuovo ma lo stato del rilascio: il rischio adesso è nei deployment non ancora allineati. Le altre tre CVE coprono buffer over-read, use-after-free e path traversal, segno che la superficie del prodotto non si ferma alla singola falla di CVE-2026-53413.
CVSS 8.3 HIGH: missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting…
CVSS 6.5 MEDIUM: missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting…
5 fonti che coprono questa storia
Kwetsbaarheden verholpen in Zoom
Zoom heeft kwetsbaarheden verholpen in Zoom Clients en Zoom VDI Client software.
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.
Zoom zero-click RCE flaws allow attackers to compromise meeting participants
A single AI-assisted researcher discovered the massive blast-radius vulnerabilities using fewer than 20 prompts on publicly available models in less than 24 hours.
Zoom Patches Zero-Click Code Execution Vulnerability
Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine.
Vulnerabilità in prodotti Zoom
Rilevate 4 nuove vulnerabilità, di cui 3 con gravità “alta”, nel software Zoom.
Part of the PlainSec briefing for 2026-08-12