ZDI-23-1541: (Pwn2Own) Microsoft Teams Incorrect Privilege Assignment Local Privilege Escalation Vulnerability
Published Oct 11, 2023
·Updated
This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft Teams. An attacker must first obtain the ability to execute script within the application window in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.
Affected Software
1 affected component
Microsoft Teams
Event History
Oct 11, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1541?
The severity of ZDI-23-1541 is rated at 7.5 on the CVSS scale.
2
How can an attacker exploit ZDI-23-1541?
An attacker must first obtain the ability to execute scripts within the Microsoft Teams application window to exploit ZDI-23-1541.
3
What are the potential impacts of ZDI-23-1541?
ZDI-23-1541 allows remote attackers to escalate privileges on affected installations of Microsoft Teams.
4
Which software is affected by ZDI-23-1541?
The vulnerability ZDI-23-1541 affects Microsoft Teams.
5
Is there a fix available for ZDI-23-1541?
As of now, please check for updates from Microsoft to address ZDI-23-1541.