Advisory Details

July 5th, 2021

(Pwn2Own) Microsoft Teams ElectronJS Frame Redirect Remote Code Execution Vulnerability

ZDI-21-772
ZDI-CAN-13612

CVE ID
CVSS SCORE 7.2, AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AFFECTED VENDORS Microsoft
AFFECTED PRODUCTS Teams
VULNERABILITY DETAILS

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Teams Desktop. An attacker must first obtain the ability to execute arbitrary JavaScript within an iframe within the application window in order to exploit this vulnerability.

The specific flaw exists within the protection of the top ElectronJS frame. By performing actions in JavaScript, an attacker can navigate the top frame to a malicious page, thereby gaining access to internal application objects. An attacker can leverage this vulnerability to execute code in the context of the current process.

ADDITIONAL DETAILS

fixed in version 1.4.00.11161


DISCLOSURE TIMELINE
  • 2021-04-19 - Vulnerability reported to vendor
  • 2021-07-05 - Coordinated public release of advisory
CREDIT oskarsv
BACK TO ADVISORIES