CERT-In Vulnerability Note
CIVN-2023-0233
Remote Code Execution Vulnerability in Microsoft Teams
Original Issue Date:August 10, 2023
Severity Rating: HIGH
Software Affected
- Microsoft Teams for Mac
- Microsoft Teams for Android
- Microsoft Teams for iOS
- Microsoft Teams for Desktop
Overview
Multiple Vulnerabilities have been reported in Microsoft Teams which could be exploited by a remote attacker to execute arbitrary code on the targeted system.
Description
These vulnerabilities could be exploited by a remote attacker to persuade the victim into joining a Teams meeting which would enable them to perform remote code execution in the context of the victim user.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, gain access to the information and cause denial of service condition on the targeted system.
Solution
Apply appropriate updates as mentioned:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29328
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29330
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29328
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29330
References
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29328
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29330
CVE Name
CVE-2023-29330
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|