ZDI-23-1767: Microsoft Teams Isolated Webview Prototype Pollution Privilege Escalation Vulnerability
Published Dec 13, 2023
·Updated
This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft Teams. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.1.
Affected Software
1 affected component
Microsoft Teams
Event History
Dec 13, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1767?
The severity of ZDI-23-1767 is rated at 7 on the CVSS scale, indicating a high level of risk.
2
How do I fix ZDI-23-1767?
To fix ZDI-23-1767, update Microsoft Teams to the latest version provided by Microsoft.
3
Who is affected by ZDI-23-1767?
Users of Microsoft Teams are affected by ZDI-23-1767 if they do not have the latest updates installed.
4
What type of attack does ZDI-23-1767 facilitate?
ZDI-23-1767 allows remote attackers to escalate privileges through user interaction.
5
What is required to exploit ZDI-23-1767?
To exploit ZDI-23-1767, the target must visit a malicious page or open a malicious file.