CVE-2023-24881HighCVSS 6.5

Microsoft Teams Information Disclosure Vulnerability

Published
May 9, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What type of information could be disclosed by this vulnerability? This vulnerability could disclose sensitive information, which might include a user's full trust token.

How could an attacker exploit the vulnerability? In a network-based attack, an attacker could host a site containing malicious code. When a target accesses that site, it could force open a full trust application and potentially obtain a user's full trust token.

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Exploitation of the vulnerability requires that a user navigate to a malicious site hosted on *.sharepoint.com.

🎯 Affected products1

  • Microsoft Teams

✅ Remediation

KBRelease Notes (Security Update) — fixed build 2.10.1

🔗 References (2)