Researchers discovered a critical flaw in Zoom that could allow an attacker to take full control of another user's device during a live meeting without any action from the victim. All Zoom Workplace clients on all supported platforms before versions 7.1.5 and 7.0.6 using end-to-end encryption settings are still vulnerable. The researchers state that the vulnerability is a memory-corruption bug that exploits Zoom's annotation feature.
Source: gadgets360-tech