Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2024-21448: Microsoft Teams for Android Information Disclosure Vulnerability

According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is information disclosure?

The attack itself is carried out locally. For example, when the score indicates that the Attack Vector is Local (AV:L) and User Interaction is Required (UI:R), this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and run a malicious application. This could lead to a local attack on the user’s device which could leak data.

Microsoft Security Response Center
#vulnerability#android#microsoft#Microsoft Teams for Android#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2024-43488: Visual Studio Code extension for Arduino Remote Code Execution Vulnerability