-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathTelegram-CVE-2020-17448
More file actions
44 lines (30 loc) · 1.53 KB
/
Copy pathTelegram-CVE-2020-17448
File metadata and controls
44 lines (30 loc) · 1.53 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
Hi World,
Please refer poc for my discovered CVE-2020-17448 in Telegram Desktop - 2.1.13 & earlier.
[ Description]
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism,
as demonstrated by use of the chat window with a filename that lacks an extension.It was observed that existing dangerous file type execution protection
in Telegram desktop application 2.1.13 & earlier versions could be bypassed by attacker by spoofing file types which leads to execution of files.
To successfully exploit issue , attacker needs to send malicious & no extension files to victim in chat window.
------------------------------------------
[VulnerabilityType Other]
Bypassing executable execution protection with no extension file
------------------------------------------
[Vendor of Product]
Telegram tdesktop
------------------------------------------
[Affected Product Code Base]
Telegram Desktop - 2.1.13 & earlier
------------------------------------------
[Attack Type Other]
Victim needs to download malicious & no extension file & once no extension file clicked by victim results into execution of malicious
executable.
------------------------------------------
[Reference]
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17448
[Timelines]
1. Report to telegram on June, 2020
2. Initial acknowledgement received from vendor on July, 2020
3. Vendor patched Vulnerability in 2.2 version & rewarded with bounty.
Regards,
Vijay Tikudave
https://in.linkedin.com/in/vijay-tikudave