Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Zoom Zero-Click RCE Vulnerability & CVSS Score Explained

PDQ
10/05/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


We're going to cover that. Also, Mac OS now in PDQ Connect. Josh is going to do a big section on that. And then we're going to play a game. How exciting, right? Super exciting. Okay, first, Zoom. All right, let's talk about Zoom, should we? All right, so last week it didn't make a ton of, well, let me back up. It made some noise about what a lot of reporters were calling a zero click, zero user interaction remote code execution inside of Zoom. The researchers outside of Zoom rated it as critical, whereas Zoom internally rated it as high, okay? So same bug, two different numbers. But here's where it comes in, is if you're not super familiar with CVSS and what all of the little, the letters mean over there, we're going to break it down. Okay, so AV is the attack vector.

TL;DR

  • A zero-click remote code execution vulnerability in Zoom was disclosed, requiring no user interaction to exploit, making it particularly dangerous for unpatched endpoints.
  • External researchers rated the Zoom bug as critical while Zoom's own team rated it as high, illustrating how CVSS scoring can vary depending on who is doing the assessment.
  • The clip begins breaking down CVSS score components — starting with attack vector (AV) — to help viewers understand what severity ratings actually mean in context.

Summary

This short-form clip from PDQ introduces a recently disclosed zero-click, zero-user-interaction remote code execution vulnerability in Zoom. The segment highlights a notable discrepancy in severity ratings: independent security researchers classified the bug as critical, while Zoom's internal team rated it as high — the same vulnerability, two different CVSS scores. The hosts use this as a jumping-off point to explain what CVSS (Common Vulnerability Scoring System) metrics actually mean in practice, beginning with the attack vector (AV) component. The clip is part of a longer episode that also covers macOS support in PDQ Connect and an interactive segment, making it a teaser for a broader community-focused show rather than a standalone deep-dive into the vulnerability itself.

Chapters

0:00 - Episode Preview
0:14 - Zoom Vulnerability Overview
0:35 - CVSS Scoring Discrepancy
0:49 - Breaking Down CVSS Metrics

Key Quotes

0:26 "It made some noise about what a lot of reporters were calling a zero click, zero user interaction remote code execution inside of Zoom."
0:35 "The researchers outside of Zoom rated it as critical, whereas Zoom internally rated it as high."
0:45 "Same bug, two different numbers."

FAQ

Why did external researchers and Zoom rate the same vulnerability differently?

The same bug can receive different CVSS scores depending on the assumptions made during scoring — such as attack complexity, scope, and environmental context. External researchers and vendors may weigh these factors differently, sometimes leading to a critical vs. high discrepancy for the same flaw.

What does 'zero-click' mean in the context of this Zoom vulnerability?

A zero-click vulnerability requires no interaction from the target user to be exploited. Unlike phishing attacks that require a user to click a link, zero-click flaws can be triggered remotely without any action on the victim's part, making them significantly more dangerous.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Security Operations
  • Threat Intelligence
  • Getting Started
  • How-To
  • Zoom vulnerability
  • Zero-click RCE
  • CVSS scoring
  • Vulnerability disclosure
  • Patch management
  • Cybersecurity news
  • Remote code execution
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Zoom Zero-Click RCE Vulnerability & CVSS Score Explained

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version