If your business relies on Zoom for client meetings, staff catch-ups, or remote consultations, a recently disclosed flaw is worth knowing about. Researchers found that the annotation tool in Zoom — the little feature that lets people draw and type on a shared screen — had a serious weakness. It allowed one meeting participant to potentially take control of another attendee’s computer, or even the presenter’s, without that person clicking anything, downloading anything, or seeing any warning on screen. The vulnerability has been patched, but it’s a useful reminder of how much trust we place in everyday tools we barely think twice about.
According to reporting from The Hacker News, the flaw sat inside Zoom’s screen annotation feature. Normally, when someone shares their screen, other attendees can use annotation tools to draw arrows, circles, or notes on top of what’s being shown — handy for walking a client through a document or pointing out something in a spreadsheet. The problem was that the way Zoom handled these annotations could be abused to hijack a session. A malicious attendee could potentially gain control over the presenter’s device, and in a nasty twist, the presenter could also gain control over an attendee’s device. No suspicious link, no dodgy attachment, no “click here to confirm” — just being present in the meeting was enough.
Zoom has since released a fix, but the flaw existed for some time before it was found and patched, and there’s no guarantee every business has actually installed the update.
It’s easy to assume vulnerabilities like this only affect large corporations with thousands of Zoom licenses. In reality, small and medium businesses across Gippsland and regional Victoria are often heavier users of video conferencing than people realise — client consultations, remote bookkeeping sessions, supplier negotiations, telehealth appointments, staff working from home or across multiple sites. A flaw that requires zero clicks is particularly dangerous because it removes the one thing most cybersecurity training focuses on: teaching staff to “think before you click.” This attack didn’t need a mistake from the victim at all.
For a small business, the fallout from something like this could include:
Unlike many of the vulnerabilities that make headlines, this issue doesn’t require complex remediation, expensive tools, or a security consultant on speed dial. Zoom has already released a patch. The fix is simply making sure everyone in your business is actually running the updated version of the app.
That said, “simple” doesn’t always mean “done.” Software update fatigue is real, and it’s common for businesses to have a mix of devices — some managed by IT, some personal laptops used for work, some old installs that haven’t been touched in months. This is exactly the kind of gap that attackers rely on.
The bigger takeaway here isn’t really about Zoom specifically — it’s about the category of software that businesses use constantly but almost never think about from a security perspective. Video conferencing tools, screen-sharing apps, chat platforms, and collaboration software have become as core to daily operations as email, yet they rarely get the same scrutiny. Most businesses have a rough idea of when their antivirus was last updated, but far fewer could say the same about their conferencing software.
This is where a basic patch management routine pays off. It doesn’t need to be complicated: a monthly check-in where someone confirms that operating systems, browsers, and the handful of key apps your business relies on (Zoom, Teams, accounting software, remote access tools) are all current. For a solo operator or small team, this might take fifteen minutes. For a business without any routine at all, it might take a bit longer the first time — but it closes off a huge number of easy attack paths.
If you have reason to believe a meeting was compromised — unusual activity on a device shortly after a call, files or settings changed without explanation, or a participant behaving oddly during a session — treat it seriously. Disconnect the affected device from your network, change passwords for any accounts accessed from that device, and have someone check for unfamiliar software or remote access tools that may have been installed. Don’t wait to see if problems “go away” on their own.
Most cybersecurity advice for small businesses focuses on training staff to spot phishing emails and suspicious attachments, and that’s still important. But this Zoom flaw is a good reminder that some risks bypass human judgement entirely. The defence isn’t vigilance — it’s simply keeping the software you rely on every day up to date. It costs nothing, takes minutes, and in this case, would have completely neutralised the threat.
If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.
(+61) 0412 440 804