Affected Systems
Zoom Workplace (all platforms) before 7.1.5 and 7.0.6; Zoom Workplace VDI Client for Windows before 7.0.11 and 6.6.16; Zoom Rooms and Zoom Meeting SDK (all platforms) before 7.1.0 and 7.1.5. Affects both screen sharers and meeting viewers.
Exploitation Status
No active exploitation reported. Patches released June-July 2026, disclosed publicly August 2026. Not listed in CISA KEV catalog. Proof-of-concept developed by A Security in under one day using publicly available AI models.
Business Impact
Critical zero-click remote code execution via annotation feature allowed any meeting participant to compromise other attendees' systems without user interaction. Buffer overflow and missing sender validation enabled malicious annotation objects to overwrite return addresses and execute arbitrary code. Vulnerability required only meeting participation—no click, download, or visible prompt. Divergence between vendor CVSS scores (6.5-8.3) and researcher assessment (9.0 CVSS 4.0) reflects dispute over user interaction requirements and impact severity.
Urgency
🟠 Within 24 hours
Recommended Actions
- Verify all Zoom clients are updated to Workplace 7.1.5/7.0.6 or later, VDI Client 7.0.11/6.6.16 or later, and Rooms/Meeting SDK 7.1.0/7.1.5 or later
- Audit Zoom client versions across endpoints using endpoint management tools or Zoom admin dashboard to identify unpatched installations
- Review meeting logs from June-August 2026 for anomalous annotation activity or unexpected client behavior during screen sharing sessions
- Disable annotation features via Zoom admin settings for high-security meetings until patch deployment is confirmed organization-wide
- Monitor endpoint detection and response (EDR) logs for suspicious process behavior originating from Zoom client processes (zoom.exe, ZoomLauncher)
