CVE-2023-24881
published 2023-07-11CVE-2023-24881: Microsoft Teams Information Disclosure Vulnerability
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.50%
71.3th percentile
Microsoft Teams Information Disclosure Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_teams | >= 2.0.0 < 2.10.1 | 2.10.1 |
| microsoft | teams | < 2.10.1 | 2.10.1 |
| msrc | microsoft_teams | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Teams Information Disclosure Vulnerability
vendor_msrc·2023-05-09·CVSS 6.5
CVE-2023-24881 [MEDIUM] CWE-200 Microsoft Teams Information Disclosure Vulnerability
Microsoft Teams Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
This vulnerability could disclose sensitive information, which might include a user's full trust token.
FAQ: How could an attacker exploit the vulnerability?
In a network-based attack, an attacker could host a site containing malicious code. When a target accesses that site, it could force open a full trust application and potentially obtain a user's full trust token.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
Exploitation of the vulnerability requires that a user navigate to a malicious site hosted on *.sharepoint.com.
Microsoft Teams: Microsoft Teams
Microsoft: Microsoft
Customer Action
GHSA
GHSA-9vvv-hwvr-q266: Microsoft Teams Information Disclosure Vulnerability
ghsa_unreviewed·2023-07-11
CVE-2023-24881 [MEDIUM] GHSA-9vvv-hwvr-q266: Microsoft Teams Information Disclosure Vulnerability
Microsoft Teams Information Disclosure Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-11
Published