CVE-2024-41145

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Dec 18, 2024
CWE ID 347

Summary

CVE-2024-41145 is a vulnerability affecting the WebView.app helper app in Microsoft Teams (work or school) version 24046.2813.2770.1094 for macOS. This issue involves a library injection weakness, where a maliciously crafted library can bypass the application's permissions by leveraging Teams's access privileges. A malicious application could exploit this vulnerability by injecting a library and starting the program, potentially gaining unauthorized access to sensitive data or system functions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share