Showing 4 vulnerabilities on this page for Zoom Clients

Signals CISA KEV Ransomware Nuclei
Zoom Communications vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Zoom Clients - Use After Free

Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.

CWE-416Aug 11, 2026
CVSS8.3v3.1EPSS0.388%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Zoom Clients - Buffer Over-read

Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.

CWE-126Aug 11, 2026
CVSS6.5v3.1EPSS0.276%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Zoom Clients - Buffer Over-write

Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.

CWE-787Aug 11, 2026
CVSS8.3v3.1EPSS0.409%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Zoom Clients for Windows - Race Condition

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

CWE-367Jul 16, 2026
CVSS7.0v3.1EPSS0.094%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX