Security Advisory – October, 2023: WebP Vulnerability Affecting Neat Frame Running Microsoft Teams in Personal Mode

Advisory ID: NEAT-SA-2023-10-10
Publication date: October 10, 2023
Last updated: October 10, 2023

Severity: High — CVSS v3.1 Base Score: 8.8 (score for the underlying libwebp vulnerability, CVE-2023-4863)

CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE ID: CVE-2023-4863

Summary

A heap buffer overflow vulnerability in libwebp, the code library used to process WebP images, could allow arbitrary code execution and can sometimes be triggered without user interaction when an application processes a malicious image.

Affected Products

ProductAffected versionsFixed version
Neat Frame running Microsoft Teams in personal modeVersions using the affected Chromium WebView at time of publicationPatched via Microsoft Teams update — see Remediation

Not affected: Neat Bar, Neat Board, Neat Bar Pro, Neat Pad, Neat Pulse Control, any devices running Zoom, and Neat Frame running Zoom Rooms.

Impact

Running Microsoft Teams in personal mode on a Neat Frame could allow a user to upload a malformed WebP image via chat, potentially triggering the vulnerability through Chromium WebView. No other Neat devices or configurations were found to be affected.

Details

Neat devices use WebP images from the Android Framework during out-of-box setup and system settings, but the interface does not allow users to open a WebP file directly, so this path is not affected. The affected path is Microsoft Teams and Zoom’s use of Chromium WebView to render images within chat; only Microsoft Teams in personal mode on Neat Frame was found to expose the vulnerable path.

Remediation

Neat worked with Microsoft to release a version containing a patched Chromium browser, anticipated late October to early November 2023. Until patches were available, administrators were advised to remind users not to click links from unknown or untrusted sources on Neat Frame devices, and to consider limiting image sharing in chat to users within their own organization.

Acknowledgements

Not applicable — based on public security research into libwebp.

References

Contact

Questions about this advisory can be directed to security@neat.no.