CVE-2024-41138
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2024-41138 is a library injection vulnerability affecting the com.microsoft.teams2.modulehost.app helper app in Microsoft Teams (work or school) version 24046.2813.2770.1094 for macOS. This issue allows a specially crafted library to be injected into the app, bypassing its access privileges. A malicious application could exploit this vulnerability by injecting a library and starting the program, thereby gaining the permissions of the vulnerable application. This could potentially lead to unauthorized access or data theft. Microsoft is urged to release a patch to address this security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Teams
Affected Vendors
- Microsoft