CVE-2026-53413
Received Received - Intake

Buffer Over-Write in Zoom Client via Annotator Function

Vulnerability report for CVE-2026-53413, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Zoom Video Communications, Inc.

Description

Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
zoom zoom_workplace to 7.1.5|end_excluding=7.0.6 (exc)
zoom zoom_workplace_vdi_client to 7.0.11|end_excluding=6.6.16 (exc)
zoom zoom_rooms to 7.1.0 (exc)
zoom zoom_meeting_sdk to 7.1.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-53413 is a buffer over-write vulnerability caused by a missing bounds check in the annotator function of Zoom Clients. This flaw may allow a meeting participant to remotely execute code on another participant's system via network access.

Detection Guidance

Detecting this vulnerability requires checking the installed version of Zoom Clients against the affected versions. Compare your installed version with the patched versions: Zoom Workplace (7.1.5 or 7.0.6), Zoom Workplace VDI Client (7.0.11 or 6.6.16), Zoom Rooms (7.1.0), and Zoom Meeting SDK (7.1.0). Use system commands to check the version, such as 'zoom --version' on Linux or checking the installed program version in Windows.

Impact Analysis

This vulnerability could allow an attacker who is a meeting participant to gain control over another participant's system. This may lead to unauthorized access, data theft, or further compromise of the affected system.

Mitigation Strategies

Immediately update all Zoom Clients to the latest patched versions: Zoom Workplace to 7.1.5 or 7.0.6, Zoom Workplace VDI Client to 7.0.11 or 6.6.16, Zoom Rooms to 7.1.0, and Zoom Meeting SDK to 7.1.0. Ensure all users and systems are updated to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53413. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart