Major security vulnerabilities in popular meeting software recently created serious safety risks for remote work. Security experts uncovered critical flaws in the screen drawing features of the platform. These security gaps allowed meeting participants to take over other connected computers without any warning.
The security issues sat directly within the interactive drawing tools that let meeting attendees type and draw on shared screens. Anyone sharing a screen could potentially hijack the computers of everyone watching the presentation. At the same time, any viewer could take total control of the screen presenter’s device. The flaw required zero action from targeted victims beyond simply joining the call. No downloads, links, or prompts appeared on screen to show an attack was happening.
The software developer released client patches in June and July to protect users. These fixes shipped about two months before researchers made details public. Cybersecurity agencies report no active exploitation of these security gaps in the wild. However, security teams urge all organizations to verify their software updates immediately.
The primary fix applies to main workplace client builds prior to versions 7.1.5 and 7.0.6.Dedicated virtual desktop systems need updates prior to versions 7.0.11 and 6.6.16.Software development kits and meeting room installations also require immediate upgrades to protected builds.
An Israeli security startup discovered these flaws during internal testing. Researchers claimed they created a functional attack script in less than one day using artificial intelligence tools. They used simple text prompts with public AI models to speed up their research. However, independent experts cannot confirm those claims because the research paper omits specific model details.
Technical reports show that drawing actions do not travel across standard networks as visual images. Instead, the meeting application packages drawings into structured digital data blocks. Receiving apps trust those data markers to calculate memory sizes. A missing memory boundary check allowed bad data to overwrite critical system addresses.
At the same time, the network dispatcher failed to verify where incoming drawing signals originated. Every viewer maintains an active data path back to the meeting host. The system accepted commands on host channels without checking sender identity. That authorization failure allowed one malicious message to reach and control every computer in the room.
Official security advisories label the main memory overwrite flaw as high severity. A secondary memory reading issue carries a medium severity rating. A third related issue addresses dynamic memory management errors. Software vendors and security researchers still debate the exact impact scores of these issues. Official records list lower severity numbers than initial security firm estimates. Official entries also note that basic user interaction is necessary for exploitation, though researchers dispute that claim.
Technical security teams urge all corporate networks to enforce auto-update policies. Modern remote work software requires regular patching to stay safe from unauthorized access. Administrators should check current software numbers against official vendor security bulletins to ensure full protection across all company devices.

