Researchers disclosed a critical remote code execution issue in the Windows ms-officecmd: URI handler that let attackers inject arguments into Microsoft application launches through crafted JSON passed to LocalBridge.exe and AppBridge.dll. The flaw affected Windows 10 and 11 and could be used to start applications including Teams, Skype, and Outlook with attacker-controlled parameters, enabling arbitrary command execution, interception of Teams traffic, exposure of the Node.js debugger, and Outlook-assisted phishing scenarios.
The researchers reported that Internet Explorer 11 and Edge Legacy on Windows 10 could invoke the malicious URI without showing an external-protocol confirmation prompt, creating a drive-by exploitation path when Teams was installed and not already running. Microsoft initially dismissed the report, later reclassified it as Critical RCE, awarded a $5,000 bounty, and released a partial fix, but the researchers said the underlying argument-injection weakness remained present on fully patched Windows 10 and Windows 11 systems at the time of publication.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The reference set includes a CVE record for CVE-2020-13699, indicating the vulnerability had been formally cataloged under that identifier. No explicit event date is provided in the content.
The researchers said Microsoft released a partial mitigation that blocked some Teams and Skype exploitation paths. They also stated the underlying argument-injection flaw remained present on patched Windows 10 and Windows 11 systems.
According to the disclosure, Microsoft initially dismissed the report but later reclassified it as a Critical remote code execution issue and awarded a $5,000 bounty. The content does not explicitly state when that reclassification and payment occurred.
Positive Security disclosed a Windows 10/11 code execution issue in the default ms-officecmd: URI handler involving LocalBridge.exe and AppBridge.dll, showing crafted JSON payloads could inject arguments and launch Microsoft applications with attacker-controlled parameters. The disclosure described impacts including arbitrary command execution, Teams traffic interception, Node.js debugger exposure, and Outlook phishing paths.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.