Vulnerability Description
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an extension.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Telegram | Telegram Desktop | <= 2.1.13 |
Related Weaknesses (CWE)
References
- https://github.com/VijayT007/Vulnerability-Database/blob/master/Telegram-CVE-202Third Party Advisory
- https://github.com/telegramdesktop/tdesktop/releases/tag/v2.2.0Release NotesThird Party Advisory
- https://security.gentoo.org/glsa/202101-34Third Party Advisory
- https://telegram.orgVendor Advisory
- https://github.com/VijayT007/Vulnerability-Database/blob/master/Telegram-CVE-202Third Party Advisory
- https://github.com/telegramdesktop/tdesktop/releases/tag/v2.2.0Release NotesThird Party Advisory
- https://security.gentoo.org/glsa/202101-34Third Party Advisory
- https://telegram.orgVendor Advisory
FAQ
What is CVE-2020-17448?
CVE-2020-17448 is a vulnerability with a CVSS score of 7.8 (HIGH). Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an ext...
How severe is CVE-2020-17448?
CVE-2020-17448 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-17448?
Check the references section above for vendor advisories and patch information. Affected products include: Telegram Telegram Desktop.