CVE-2020-17448: High severity telegram vulnerability
Published Aug 11, 2020
·Updated
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an extension.
Affected Software
1 affected component
Telegram Telegram Desktop<=2.1.13
Event History
Aug 11, 2020
CVE Published
via MITRE·04:02 PM
Data Sourced
via MITRE·04:02 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Telegram Desktop vulnerability?
The vulnerability ID for this Telegram Desktop vulnerability is CVE-2020-17448.
2
What is the severity of CVE-2020-17448?
The severity of CVE-2020-17448 is high (7.8).
3
What is the affected software for CVE-2020-17448?
The affected software for CVE-2020-17448 is Telegram Desktop through version 2.1.13.
4
How does the vulnerability in Telegram Desktop work?
The vulnerability in Telegram Desktop allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism by using a chat window with a filename that lacks an extension.
5
How can I fix the CVE-2020-17448 vulnerability?
To fix the CVE-2020-17448 vulnerability, update Telegram Desktop to version 2.2.0 or later.