Skip to content
feed: live
>_ 0dayNews
zoom

Zero-Click RCE in Zoom Annotation — Patch Now

A flaw in Zoom's annotation tool let any meeting participant execute code on another attendee's machine — zero clicks required. Update Zoom clients now.

Zero-Click RCE in Zoom Annotation — Patch Now
Image: AI-generated — no human photographer / 0dayNews AI Cover (comfyui) · Generated on-site infrastructure — no external license
fuse Marisol "Fuse" Delgado · Published · 1 min read

Zoom has patched a zero-click code execution vulnerability in its annotation feature that could have let any meeting participant execute code on another attendee’s machine. No click. No download. No prompt — just being in the call was enough.

What the Flaw Did

The vulnerability sat in Zoom’s annotation tool: the drawing-and-typing overlay that participants use when someone shares their screen. The Hacker News and SecurityWeek both report the flaw ran in both directions — a presenter sharing their screen could have code executed on their machine by any watcher, and watchers could likewise be targeted by the presenter. Nothing on-screen indicated it was happening.

CVE assignment and CVSS scores are pending. Check Zoom’s Security Bulletins page for the authoritative advisory, affected version ranges, and patch details as they publish.

What to Do

  1. Update Zoom clients now. The patch is out. Zero-click RCE with no victim interaction is a front-of-queue item, not a scheduled maintenance task.
  2. Verify auto-update is actually landing on endpoints. Zoom updates when the client opens — machines that have been offline or closed since the patch release haven’t received it.
  3. Pull version data from MDM or endpoint tooling. Know what the fleet is running before assuming the rollout is complete.
  4. Disable annotation as a short-term workaround if the rollout can’t finish before meetings resume today. Meeting hosts can restrict or disable annotation in Zoom account settings, which removes the attack surface while patching catches up.

Priority Call

Same-day patch. If your Zoom clients aren’t on the patched version before the next round of enterprise calls, disable annotation host-side in the interim and treat this as a P1 rollout.

It’s a heavy patch day — Microsoft shipped fixes for 421 CVEs including an actively exploited Windows kernel driver zero-day. Don’t let Zoom slip because Microsoft’s volume is louder.

Found this useful? Share it.