Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN842
_____________________________________________________________________

DATE                : 12/08/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Zoom Workplace all supported
platforms before version 7.1.5 and 7.0.6 in their respective branches,
    Zoom Workplace VDI Client for Windows before versions 7.0.11 and
                       6.6.16 in their respective branches,
       Zoom Rooms all supported platforms before version 7.1.0,
      Zoom Meeting SDK all supported platforms before version 7.1.0.
 
=====================================================================
https://www.zoom.com/en/trust/security-bulletin/zsb-26015/
https://www.zoom.com/en/trust/security-bulletin/zsb-26017/
https://www.zoom.com/en/trust/security-bulletin/zsb-26018/
https://www.zoom.com/en/trust/security-bulletin/zsb-26016/
_____________________________________________________________________


Zoom Clients - Buffer Over-write

    Bulletin: ZSB-26015
    CVEID: CVE-2026-53413
    CVSS Severity: High
    CVSS Score: 8,3
    CVSS Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Description:

Missing bounds check in the annotator function of Zoom Clients allows
buffer over-write, which may allow a meeting participant to achieve
remote code execution of another participant via network access.

 
Users can help keep themselves secure by applying the latest updates
available at https://zoom.us/download.

Affected Products:

    Zoom Workplace all supported platforms before version 7.1.5 and
7.0.6 in their respective branches
    Zoom Workplace VDI Client for Windows before versions 7.0.11 and
6.6.16 in their respective branches
    Zoom Rooms all supported platforms before version 7.1.0
    Zoom Meeting SDK all supported platforms before version 7.1.0

Source:

Reported by Idan Levcovich, A Security


Revision 	Date 	Description
1.0             08/11/2026 	

Initial publication.
_____________________________________________________________________


Zoom Clients - Use After Free

    Bulletin: ZSB-26017
    CVEID: CVE-2026-53415
    CVSS Severity: High
    CVSS Score: 8,3
    CVSS Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Description:

Use after Free in the annotator function of Zoom Clients may allow a
meeting participant to achieve remote code execution of another
participant via network access.
 

Users can help keep themselves secure by applying the latest updates
available at https://zoom.us/download.

Affected Products:

    Zoom Workplace all supported platforms before version 7.1.5 and
7.0.6 in their respective branches
    Zoom Workplace VDI Client for Windows before versions 7.0.11 and
6.6.16 in their respective branches
    Zoom Rooms all supported platforms before version 7.1.5
    Zoom Meeting SDK all supported platforms before version 7.1.5

Source:

Reported by Zoom Offensive Security

Revision 	Date 	Description
1.0             08/11/2026 	

Initial publication.
_____________________________________________________________________


Zoom VDI - Path Traversal

    Bulletin: ZSB-26018
    CVEID: CVE-2026-53416
    CVSS Severity: High
    CVSS Score: 7,1
    CVSS Vector String: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description:

Path traversal in Zoom VDI Client and Plugins may allow an authenticated
user to conduct information disclosure via local access.

 

Users can help keep themselves secure by applying the latest updates
available at https://zoom.us/download.

Affected Products:

    Zoom Workplace VDI Client for Windows before versions 7.0.11 and
6.6.15 in their respective branches.

    Zoom Workplace VDI Plugins all supported platforms before 7.0.11
and 6.6.15 in their respective branches.

Source:

Reported by CK Tan from the XOR team at JPMorgan Chase


Revision 	Date 	Description
1.0             08/11/2026 	

Initial publication.
_____________________________________________________________________


Zoom Clients - Buffer Over-read

    Bulletin: ZSB-26016
    CVEID: CVE-2026-53414
    CVSS Severity: Medium
    CVSS Score: 6,5
    CVSS Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Description:

Missing bounds check in the annotator function of Zoom Clients allows
buffer over-read, which may allow a meeting participant to conduct a
denial of service on another participant via network access.


Users can help keep themselves secure by applying the latest updates
available at https://zoom.us/download.

Affected Products:

    Zoom Workplace all supported platforms before version 7.1.5 and
7.0.6 in their respective branches
    Zoom Workplace VDI Client for Windows before versions 7.0.11 and
6.6.16 in their respective branches
    Zoom Rooms all supported platforms before version 7.1.0
    Zoom Meeting SDK all supported platforms before version 7.1.0

Source:

Reported by Idan Levcovich, A Security


Revision            Date 	Description
1.0                 08/11/2026

=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




