Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client
Everyone viewing might have taken over the presenter's computer, and anyone sharing their screen during a Zoom session could have taken over everyone else's.
The annotation tool, which allows participants to type and draw on a shared screen, was flawed because it just required the victim to attend the meeting. There was no prompt, no download, no click, and no visual indication that it had occurred.
The patches are not brand-new. No exploitation has been reported as of publication, and client updates were provided in June and July, around two months prior to the issues being made public. The Known Exploited Vulnerabilities catalog maintained by CISA does not contain any of the three identifiers.
The versions that close them:
Zoom Workplace, all supported platforms, before 7.1...

