CVE-2020-17448

HIGH

Telegram Desktop <2.1.13 - Info Disclosure

Title source: llm
STIX 2.1

Description

Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an extension.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_misc
https://telegram.org
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/telegramdesktop/tdesktop/releases/tag/v2.2.0
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202101-34

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 44.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (1)
telegram/telegram_desktop < 2.1.13
Published Aug 11, 2020
Tracked Since Feb 18, 2026