(Pwn2Own) Microsoft Teams ElectronJS Frame Redirect Remote Code Execution Vulnerability
Vulnerability Details
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Teams Desktop. An attacker must first obtain the ability to execute arbitrary JavaScript within an iframe within the application window in order to exploit this vulnerability.
The specific flaw exists within the protection of the top ElectronJS frame. By performing actions in JavaScript, an attacker can navigate the top frame to a malicious page, thereby gaining access to internal application objects. An attacker can leverage this vulnerability to execute code in the context of the current process.
Additional Details
fixed in version 1.4.00.11161
Disclosure Timeline
- 2021-04-19 - Vulnerability reported to vendor
- 2021-07-05 - Coordinated public release of advisory
Credit
oskarsv