Microsoft Teams Race: Event Subsystem Use-After-Free in AV Calls
CVE-2023-38538 Published on October 4, 2023
A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.
Products Associated with CVE-2023-38538
stack.watch emails you whenever new vulnerabilities are published in WhatsApp or Microsoft Teams. Just hit a watch button to start following.
Affected Versions
Facebook WhatsApp Desktop for Mac:- Before 2.2338.12 is affected.
- Before 2.2320.2 is affected.
- Before 2.23.10.77 is affected.
- Before 2.23.10.77 is affected.
- Before 2.23.10.77 is affected.
- Before 2.23.10.77 is affected.
Exploit Probability
EPSS
0.09%
Percentile
25.62%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.