CVE-2024-43604
Outlook for Android Elevation of Privilege Vulnerability
In short
A vulnerability in Outlook for Android allows an attacker to gain elevated privileges on the device. An attacker with access to the device could exploit this flaw to perform actions that normally require higher permissions.
Technical detail
CWE-1220 indicates improper restriction of rendered UI layers or frames, allowing privilege escalation through UI-based attacks. An attacker with local or physical access to the affected device can bypass permission boundaries in Outlook for Android to execute operations with elevated privileges.
Summary generated and translated by AI from the official description.
Outlook for Android Elevation of Privilege Vulnerability
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Affected products
Microsoft · Microsoft Outlook for AndroidWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →