Outlook for Android: Directory...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

There is a directory traversal issue in attachment downloads in Outlook for Android. There is no path sanitization on the attachment filename in the app. If the email account is a Hotmail account, this will be sanitized by the server, but for other accounts it will not be. This allows a file to be written anywhere on the filesystem that the Outlook app can access when an attached image is viewed in the Outlook app. This bug has the following limitations: 1) the email address has to be a non-Hotmail address 2) the file can not overwrite an existing file (append happens in this case), it has to be a file that doesn't already exist. 3) the user has to click the image and view it, it is not sufficient just to view the thumbnail in the message. It is possible to modify a database using this bug by placing a journal file in the databases directory. Below is a PoC of an email that causes this issue. Attached is a python script that will send an email that causes this issue (don't forget...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息