Code Injection in Slack Technologies, Inc. products - #VU46184
Published: September 1, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when processing input passed to the application. A remote attacker can create a specially crafted web page, share a specially crafted post with the victim, trick the victim into clicking on a link or image and execute arbitrary code on the system with privilege of the current user.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Slack for Windows
Slack for macOS
Remediation
Slack for Windows - update to 4.4.0
Slack for macOS - update to 4.4.0