SECURITY Signal 164
Zoom Workplace RCE lets meeting attendees control devices; AI agent found it with 20 prompts
A.Security found a critical remote code execution flaw in Zoom Workplace, allowing any meeting participant to take over another's device, using an AI agent with just 20 prompts.
This demonstrates that AI-assisted vulnerability research can quickly find critical flaws in proprietary software, collapsing the barrier to nation-state-class exploits. Engineers must assume that even closed-source applications are vulnerable and prioritize rapid patching and update deployment. The fact that the exploit works without using the annotation feature means the attack surface is larger than expected.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The vulnerability is a buffer overrun in Zoom's annotation library, allowing remote code execution without using the whiteboard.
It affects Zoom Workplace before 7.0.6 and before 7.1.5 on the fast track branch; Zoom has fixed it in current versions.
A.Security used an AI agent with only 20 prompts to develop the exploit, highlighting the ease of AI-assisted vulnerability discovery.
THE CLUSTER
↗