ZDI-23-1282: Microsoft Teams Pluginhost Prototype Pollution Privilege Escalation Vulnerability
Published Aug 30, 2023
·Updated
This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft Teams. An attacker must first obtain the ability to execute script within the application window in order to exploit this vulnerability.
Affected Software
1 affected component
Microsoft Teams
Event History
Aug 30, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1282?
The severity of ZDI-23-1282 is considered high due to its potential for privilege escalation.
2
How do I fix ZDI-23-1282?
To fix ZDI-23-1282, ensure that you update Microsoft Teams to the latest version provided by Microsoft.
3
What types of attacks can ZDI-23-1282 enable?
ZDI-23-1282 can enable remote attackers to escalate privileges within the Microsoft Teams application.
4
What is required for an attacker to exploit ZDI-23-1282?
An attacker must first gain the capability to execute scripts within the Microsoft Teams application window to exploit ZDI-23-1282.
5
Which software is affected by ZDI-23-1282?
ZDI-23-1282 affects all installations of Microsoft Teams.