Security Advisory – October, 2023: WebP Vulnerability Affecting Neat Frame Running Microsoft Teams in Personal Mode
Advisory ID: NEAT-SA-2023-10-10
Publication date: October 10, 2023
Last updated: October 10, 2023
Severity: High — CVSS v3.1 Base Score: 8.8 (score for the underlying libwebp vulnerability, CVE-2023-4863)
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE ID: CVE-2023-4863
Summary
A heap buffer overflow vulnerability in libwebp, the code library used to process WebP images, could allow arbitrary code execution and can sometimes be triggered without user interaction when an application processes a malicious image.
Affected Products
| Product | Affected versions | Fixed version |
| Neat Frame running Microsoft Teams in personal mode | Versions using the affected Chromium WebView at time of publication | Patched via Microsoft Teams update — see Remediation |
Not affected: Neat Bar, Neat Board, Neat Bar Pro, Neat Pad, Neat Pulse Control, any devices running Zoom, and Neat Frame running Zoom Rooms.
Impact
Running Microsoft Teams in personal mode on a Neat Frame could allow a user to upload a malformed WebP image via chat, potentially triggering the vulnerability through Chromium WebView. No other Neat devices or configurations were found to be affected.
Details
Neat devices use WebP images from the Android Framework during out-of-box setup and system settings, but the interface does not allow users to open a WebP file directly, so this path is not affected. The affected path is Microsoft Teams and Zoom’s use of Chromium WebView to render images within chat; only Microsoft Teams in personal mode on Neat Frame was found to expose the vulnerable path.
Remediation
Neat worked with Microsoft to release a version containing a patched Chromium browser, anticipated late October to early November 2023. Until patches were available, administrators were advised to remind users not to click links from unknown or untrusted sources on Neat Frame devices, and to consider limiting image sharing in chat to users within their own organization.
Acknowledgements
Not applicable — based on public security research into libwebp.
References
Contact
Questions about this advisory can be directed to security@neat.no.