Zoom patches Zoomsday zero-click RCE in annotator
Zoom released patches for four vulnerabilities, including a zero-click remote code execution flaw in its annotator that could run code on meeting participants’ machines.
On Tuesday, Zoom announced patches for four vulnerabilities across its supported platforms, including a zero-click remote code execution flaw in the annotator feature discovered by security firm A Security and labeled Zoomsday. A Security identified three defects in the annotator protocol and a fourth issue affecting Workplace VDI components.
The most severe defect, CVE-2026-53413, is a memory corruption vulnerability that A Security demonstrated could allow one meeting participant to execute code on another participant’s machine without any interaction. A Security reported the annotator uses a proprietary protocol that opens a direct channel between a viewer and a sharer and that every Zoom client automatically parses incoming annotation messages. A missing bound check let specially crafted messages overwrite memory and enable remote code execution.
A second annotator bug, CVE-2026-53414, is another missing bound check that could cause a buffer overread and allow an attacker to trigger a denial-of-service for targeted participants. A Security also reported CVE-2026-53415, a use-after-free flaw that Zoom had already identified before the report. Separately, Zoom patched CVE-2026-53416, a path traversal issue in Workplace VDI components that could disclose information.
A Security wrote, “The exploit enables attackers to either join or host a meeting, target any participant, and take over their machine with no required action from the victim and no visual cue indicating the compromise.” The firm delayed public disclosure until client patches and server-side mitigations were available to customers.
Zoom listed the patched builds as Workplace versions 7.1.5 and 7.0.6, Rooms version 7.1.5, and Meeting SDK version 7.1.5 for all supported platforms. For virtual desktop infrastructure, Zoom provided Workplace VDI Client for Windows versions 7.0.11 and 6.6.16 and Workplace VDI Plugins versions 7.0.11 and 6.6.15.
Administrators and users should update to the patched builds promptly. Zoom published technical details and guidance, including affected versions and mitigations, on its security bulletin page.








