Microsoft has released emergency security updates for Edge, Teams, and Skype to patch two zero-day vulnerabilities in open-source libraries used by all three products.

The first vulnerability (CVE-2023-4863) is caused by a heap buffer overflow weakness in the WebP code library (libwebp). It can cause crashes or even allow code execution.
The second bug (CVE-2023-5217) is also caused by a heap buffer overflow weakness in the VP8 encoding of the libvpx video codec library. It leads to app crashes and allows code execution, after successful exploitation.
See also: Exim: Fixes three zero-day vulnerabilities
The libwebp library is used by a large number of projects to encode and decode images in WebP format. It is used, for example, by programs such as Safari, Mozilla Firefox, Microsoft Edge, Opera , as well as native Android web browsers and popular applications such as 1Password and Signal.
libvpx is used for VP8 and VP9 video encoding and decoding by desktop video playback software and by streaming services such as Netflix, YouTube , and Amazon Prime Video.
Microsoft discovered the zero-day vulnerabilities and released emergency security updates.
See also: Progress Software fixes critical vulnerability in WS_FTP Server

The two vulnerabilities affect a limited number of Microsoft products. The company patched Microsoft Edge, Microsoft Teams for Desktop, Skype for Desktop, and Webp Image Extensions for CVE-2023-4863, and Microsoft Edge for CVE-2023-5217.
Microsoft Store will automatically update all affected Webp Image Extensions users. However, the security update will not be installed if automatic updates for Microsoft Store are disabled.
Exploiting vulnerabilities in spyware attacks
Both vulnerabilities appear to have been exploited by hackers . Researchers from Google's Threat Analysis Group (TAG) and Citizen Lab revealed that malicious users used the zero-day vulnerability CVE-2023-5217 to deploy Cytrox's Predator spyware .
See also: Google: Fixes fifth Chrome zero-day this year
Regarding CVE-2023-4863, Google had said when it first discovered it: “Access to error details and links may remain limited until the majority of users receive the fix.”
“We will also maintain restrictions if the bug exists in a third-party library that other projects similarly depend on, but have not yet been fixed“.
Although there are no details about the attacks exploiting the CVE-2023-4863 vulnerability, the bug was reported by Apple Security Engineering and Architecture (SEAR) and Citizen Lab, for targeted spyware.
The critical security updates released by Microsoft are critical to maintaining the security of systems. It is important for users to apply these updates promptly to minimize the risk of malware infection.
Source: www.bleepingcomputer.com
