Highlights

  • Team of researchers finds 4 vulnerabilities in Microsoft Teams
  • Microsoft Teams issues could compromise information, cause app crashes
  • Positive Security disclosed Teams issues to Microsoft in March 2021

Latest news

Under-19 World Cup: Sooryavanshi fires India to record-extending sixth title with a knock for the ages

Under-19 World Cup: Sooryavanshi fires India to record-extending sixth title with a knock for the ages

Vaibhav Sooryavanshi smashes second fastest hundred, most sixes in U19 World Cup

Vaibhav Sooryavanshi smashes second fastest hundred, most sixes in U19 World Cup

'Can't compel woman to complete pregnancy': SC allows minor to terminate 30-week pregnancy

'Can't compel woman to complete pregnancy': SC allows minor to terminate 30-week pregnancy

31 killed, 169 injured in suicide attack at Shia mosque in Pakistan's capital Islamabad

31 killed, 169 injured in suicide attack at Shia mosque in Pakistan's capital Islamabad

Three Delhi Jal Board engineers suspended over biker's death in west Delhi construction pit

Three Delhi Jal Board engineers suspended over biker's death in west Delhi construction pit

India pacer Harshit Rana set to be ruled out of T20 World Cup

India pacer Harshit Rana set to be ruled out of T20 World Cup

Oakley Meta HSTN Smart Glasses Review: The Most Livable Smart Glasses Yet?

Oakley Meta HSTN Smart Glasses Review: The Most Livable Smart Glasses Yet?

Meghalaya mine blast: Two persons arrested as CM warns of strict action

Meghalaya mine blast: Two persons arrested as CM warns of strict action

Security vulnerabilities found in Microsoft Teams by researchers

A team of researchers from Positive Security found four vulnerabilities in Microsoft Teams, only one of which has been patched so far.

Security vulnerabilities found in Microsoft Teams by researchers

A team of researchers from Positive Security found four vulnerabilities in Microsoft Teams, they announced in a blog post. A total of four vulnerabilities were found, which could allow an attacker to spoof link previews, access internal Microsoft services, leak IP addresses, and DDoS the teams App on Android.

The team reportedly found the issues while researching the URL preview feature in Teams, Positive Security co-founder Fabian Bräunlein said.

Four vulnerabilities found in Microsoft Teams

One of the vulnerabilities is a Server-Side Request Forgery issue, which could leak information such as the response time, code, size, and open graph data. Another is a spoofing attack, which could open a different link than what was expected by the user when clicking a preview link, leading to a possible phishing attack.

A third vulnerability could allow leaking a user's IP address and user agent data by sending a message with a specially crafted link preview on Android.

The fourth, and potentially most serious vulnerability, allows a malicious attacker to crash the Teams app on Android completely, by sending a message with an invalid preview link. Opening the chat or conversation with the bad link will then repeatedly crash the Teams app.

Also Read: Apple iPhone 13 to be made in India: all you need to know

Microsoft issues fix for one issue

Positive Security say that they disclosed these vulnerabilities to Microsoft on March 10, 2021. However, they claim that Microsoft has only patched one of the four mentioned issues, concerning the IP leak on Android.

Bräunlein said that the DDoS issue could ‘become annoying’ for some users, but only the link spoofing vulnerability is likely to be used in serious attacks.

ADVERTISEMENT

Up Next

Security vulnerabilities found in Microsoft Teams by researchers

Security vulnerabilities found in Microsoft Teams by researchers

Oakley Meta HSTN Smart Glasses Review: The Most Livable Smart Glasses Yet?

Oakley Meta HSTN Smart Glasses Review: The Most Livable Smart Glasses Yet?

Lava Blaze Duo 3 review: Two displays for the price of one, but does it make sense?

Lava Blaze Duo 3 review: Two displays for the price of one, but does it make sense?

Redmi Note 15 Pro+ Review: A serious upgrade that plays it safe

Redmi Note 15 Pro+ Review: A serious upgrade that plays it safe

Vivo X200T vs Vivo X200 FE: Future-ready muscle or compact finesse?

Vivo X200T vs Vivo X200 FE: Future-ready muscle or compact finesse?

Redmi Note 15 Pro+ First Look: Bigger battery, brighter screen, sharper focus

Redmi Note 15 Pro+ First Look: Bigger battery, brighter screen, sharper focus

ADVERTISEMENT

editorji-whatsApp

More videos

Realme Buds Clip review: Surprisingly good, if you know what you’re buying

Realme Buds Clip review: Surprisingly good, if you know what you’re buying

Realme P4 Power 5G Review:29 Hours later, it still wouldn’t die

Realme P4 Power 5G Review:29 Hours later, it still wouldn’t die

Vivo X200T Review: A new kind of flagship in Vivo’s lineup

Vivo X200T Review: A new kind of flagship in Vivo’s lineup

Realme Pad 3 5G review: A productivity tablet that finally makes sense

Realme Pad 3 5G review: A productivity tablet that finally makes sense

Realme P4 Power 5G First Look: 10,001mAh battery, crammed into a slim design

Realme P4 Power 5G First Look: 10,001mAh battery, crammed into a slim design

Zeiss Batis 85mm f/1.8 and Batis 18mm f/2.8 review: Built for purists

Zeiss Batis 85mm f/1.8 and Batis 18mm f/2.8 review: Built for purists

GoPro Max 2 Review: GoPro’s Most Creative Camera Yet

GoPro Max 2 Review: GoPro’s Most Creative Camera Yet

Logitech MX Master 4 Review: A masterclass on improving perfection

Logitech MX Master 4 Review: A masterclass on improving perfection

X implements tech measures to prevent Grok from generating sexualised AI content

X implements tech measures to prevent Grok from generating sexualised AI content

CMF Headphone Pro review: Big style, bigger battery, bold sound all for ₹7,999

CMF Headphone Pro review: Big style, bigger battery, bold sound all for ₹7,999

Editorji Technologies Pvt. Ltd. © 2022 All Rights Reserved.