← back
CVE-2024-7014highobserved exploitationCWE-20

Improper multimedia file attachment validation in Telegram for Android app

63Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 7.1epss 1.4%
from disclosure to weapon236 days
Published on NVDJul 23
1st PoC+236d
VulnCheckJul 22
exploitation probability
1.4%top 31% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.