CVE Tools
Back to feed
PoC public Zoom Workplace rce Zoom privilege-escalation

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

A Security has disclosed a proof-of-concept for three vulnerabilities in the Zoom Workplace annotation feature, which could enable remote code execution without user interaction. The issues affect Zoom Workplace versions prior to 7.1.5 and 7.0.6, as well as specific VDI Client and Meeting SDK versions. Identified as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, these flaws stem from improper handling of structured data within the drawing tool.