📦

zoom

Vendor: zoom

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 6 Remote Access
Total CVEs 103 Total Indexed
Avg. EPSS 1.62% Exploit Prob.
Latest CVE CVE-2026-0998 Feb 16

Security Vulnerability Index

Page 7 / 11
6.5 CVSS

In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a machine remains vulnerable if the Zoom Client was installed in the past and then uninstalled. Blocking exploitation requires additional steps, such as the ZDisableVideo preference and/or killing the web server, deleting the ~/.zoomus directory, and creating a ~/.zoomus plain file.

EPSS: 3.52%
6.5 CVSS

In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.

EPSS: 2.00%
9.8 CVSS

Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom server in order to invoke functionality in the target client. This allows the attacker to remove attendees from meetings, spoof messages from users, or hijack shared screens.

EPSS: 3.49%
8.8 CVSS
CVE-2017-15049
RCE Exploit Found

The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.

EPSS: 17.05%
8.8 CVSS
CVE-2017-15048
Exploit Found

Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.

EPSS: 10.16%