CVE-2020-10146
Last modified
CVE-2020-10146 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as authentication tokens and to possibly execute arbitrary commands. This vulnerability was fixed for all Teams users in the online service on or around October 2020.. EPSS estimates a 1.89% chance of exploitation in the next 30 days.
Description
The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as authentication tokens and to possibly execute arbitrary commands. This vulnerability was fixed for all Teams users in the online service on or around October 2020.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Teams | < 2020-10-29 |
References
- https://github.com/oskarsve/ms-teams-rceExploit, Third Party Advisory
- https://github.com/oskarsve/ms-teams-rceExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10146?
How severe is CVE-2020-10146?
How do I fix CVE-2020-10146?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-10138Acronis Cyber Backup 12.5 and Cyber Protect 15 include an Op…7.8
- CVE-2020-10139Acronis True Image 2021 includes an OpenSSL component that s…7.8
- CVE-2020-1014An elevation of privilege vulnerability exists in the Micros…7.8
- CVE-2020-10140Acronis True Image 2021 fails to properly set ACLs of the C:…7.3
- CVE-2020-10143Macrium Reflect includes an OpenSSL component that specifies…7.8
- CVE-2020-10145The Adobe ColdFusion installer fails to set a secure access-…7.8
- CVE-2020-10148The SolarWinds Orion API is vulnerable to an authentication …9.8
- CVE-2020-1015An elevation of privilege vulnerability exists in the way th…7.8
- CVE-2020-1016An information disclosure vulnerability exists when the Wind…5.5
- CVE-2020-1017An elevation of privilege vulnerability exists in the way th…7.8
- CVE-2020-10173Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices…8.8
- CVE-2020-10174init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03…7
Are you affected by CVE-2020-10146?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
