CVE-2024-41145
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Dec 18, 2024
CWE ID 347
Summary
CVE-2024-41145 is a vulnerability affecting the WebView.app helper app in Microsoft Teams (work or school) version 24046.2813.2770.1094 for macOS. This issue involves a library injection weakness, where a maliciously crafted library can bypass the application's permissions by leveraging Teams's access privileges. A malicious application could exploit this vulnerability by injecting a library and starting the program, potentially gaining unauthorized access to sensitive data or system functions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Teams
Affected Vendors
- Microsoft