Multiple flaws in Microsoft macOS apps unpatched despite potential risks
ID: a1b5d67d-24b3-5494-b785-1fd997434f18
STIX ID: report--a1b5d67d-24b3-5494-b785-1fd997434f18
Feed Name: The Register (Security)
Cisco Talos disclosed eight vulnerabilities across Microsoft macOS applications (Excel, OneNote, Outlook, PowerPoint, Teams, Word) that stem from disabled library validation and entitlements allowing potential library injection; if exploited, an attacker could inherit app entitlements to access protected resources (camera, microphone, files, keylogging) and escalate privileges. Talos did not publish a working exploit; Microsoft considers the issues low risk, has removed the risky entitlement from Teams and OneNote but left other Office apps unchanged.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
