CVE-2020-25824
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Telegram Desktop through 2.4.3 does not require passcode entry upon pushing the Export key within the Export Telegram Data wizard. The threat model is a victim who has voluntarily opened Export Wizard but is then distracted. An attacker then approaches the unattended desktop and pushes the Export key. This attacker may consequently gain access to all chat conversation and media files.
Telegram Desktop versiones hasta 2.4.3, no requiere el ingreso de un código de acceso al presionar la tecla Exportar dentro del asistente Export Telegram Data. El modelo de amenaza es una víctima que voluntariamente ha abierto Export Wizard, pero luego es distraído. Un atacante luego se acerca al escritorio desatendido y presiona la tecla Export. En consecuencia, este atacante puede conseguir acceso a todas las conversaciones de chat y archivos multimedia
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-09-23 CVE Reserved
- 2020-10-14 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/soheilsamanabadi/vulnerability/blob/main/Telegram-Desktop-CVE-2020-25824 | Third Party Advisory | |
https://github.com/telegramdesktop/tdesktop/releases/tag/v2.4.3 | Release Notes | |
https://www.Telegram.org | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/202101-34 | 2021-07-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Telegram Search vendor "Telegram" | Telegram Desktop Search vendor "Telegram" for product "Telegram Desktop" | <= 2.4.3 Search vendor "Telegram" for product "Telegram Desktop" and version " <= 2.4.3" | - |
Affected
|