CVE-2026-53413 PUBLISHED

Zoom Clients - Buffer Over-write

Assigner: Zoom
Reserved: 09.06.2026 Published: 11.08.2026 Updated: 12.08.2026

Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS Score: 8.3

Product Status

Vendor Zoom Communications
Product Zoom Clients
Versions Default: unaffected
  • Version see references is affected

References

Problem Types

  • CWE-787 Out-of-bounds write CWE