{"data":{"id":"d4971383-32c3-4eb5-9994-10dd6fe09da5","title":"Zoom zero-click RCE flaws allow attackers to compromise meeting participants","summary":"Zoom has fixed four vulnerabilities, including two zero-click RCE (remote code execution, where attackers can run malicious commands on a system without user interaction) flaws in its text annotation feature that allow attackers in a meeting to compromise all other participants' systems silently. A researcher discovered these memory corruption bugs (where malicious input corrupts how data is stored in memory) using an AI agent in under 24 hours, demonstrating how AI tools are making sophisticated exploits accessible beyond elite attackers.","solution":"Zoom recommends updating to versions 7.1.5 and 7.0.6 for most client applications, versions 7.0.11 and 6.6.15 for Zoom Workplace VDI Client, and version 7.1.0 for Zoom Rooms and Zoom Meeting SDK. As interim measures before patching, organizations can disable end-to-end encryption (E2EE, encryption that only sender and receiver can read) so Zoom servers can filter malicious annotation messages, or restrict meeting access using waiting rooms, passcodes, authenticated-users-only settings, and minimum version requirements for clients.","labels":["security"],"sourceUrl":"https://www.csoonline.com/article/4208223/zoom-zero-click-rce-flaws-allow-attackers-to-compromise-meeting-participants.html","publishedAt":"2026-08-11T22:56:27.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":["other"],"issueType":"news","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Zoom"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-11T22:56:27.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}