Highlights

  • Team of researchers finds 4 vulnerabilities in Microsoft Teams
  • Microsoft Teams issues could compromise information, cause app crashes
  • Positive Security disclosed Teams issues to Microsoft in March 2021

Latest news

AAP calls Punjab district panchayat win historic, eyes Gujarat local body polls

AAP calls Punjab district panchayat win historic, eyes Gujarat local body polls

Gujarat AAP MLA Chaitar Vasava questions police action against tribal villagers in Banaskantha

Gujarat AAP MLA Chaitar Vasava questions police action against tribal villagers in Banaskantha

Sitharaman introduced Securities Markets Code Bill in Lok Sabha, proposes to send it to parliamentary committee

Sitharaman introduced Securities Markets Code Bill in Lok Sabha, proposes to send it to parliamentary committee

OnePlus 15R review: A clear shift in what the R-series stands for

OnePlus 15R review: A clear shift in what the R-series stands for

PM Modi departs for Oman on last leg of three-nation visit

PM Modi departs for Oman on last leg of three-nation visit

India closes visa application centre in Bangladesh capital due to security situation

India closes visa application centre in Bangladesh capital due to security situation

Congress misleading public on National Herald case, matter still in court: BJP

Congress misleading public on National Herald case, matter still in court: BJP

Pakistan to sell 100 pc stake in PIA after bidders demand complete control post-privatisation

Pakistan to sell 100 pc stake in PIA after bidders demand complete control post-privatisation

Security vulnerabilities found in Microsoft Teams by researchers

A team of researchers from Positive Security found four vulnerabilities in Microsoft Teams, only one of which has been patched so far.

Security vulnerabilities found in Microsoft Teams by researchers

A team of researchers from Positive Security found four vulnerabilities in Microsoft Teams, they announced in a blog post. A total of four vulnerabilities were found, which could allow an attacker to spoof link previews, access internal Microsoft services, leak IP addresses, and DDoS the teams App on Android.

The team reportedly found the issues while researching the URL preview feature in Teams, Positive Security co-founder Fabian Bräunlein said.

Four vulnerabilities found in Microsoft Teams

One of the vulnerabilities is a Server-Side Request Forgery issue, which could leak information such as the response time, code, size, and open graph data. Another is a spoofing attack, which could open a different link than what was expected by the user when clicking a preview link, leading to a possible phishing attack.

A third vulnerability could allow leaking a user's IP address and user agent data by sending a message with a specially crafted link preview on Android.

The fourth, and potentially most serious vulnerability, allows a malicious attacker to crash the Teams app on Android completely, by sending a message with an invalid preview link. Opening the chat or conversation with the bad link will then repeatedly crash the Teams app.

Also Read: Apple iPhone 13 to be made in India: all you need to know

Microsoft issues fix for one issue

Positive Security say that they disclosed these vulnerabilities to Microsoft on March 10, 2021. However, they claim that Microsoft has only patched one of the four mentioned issues, concerning the IP leak on Android.

Bräunlein said that the DDoS issue could ‘become annoying’ for some users, but only the link spoofing vulnerability is likely to be used in serious attacks.

ADVERTISEMENT

Up Next

Security vulnerabilities found in Microsoft Teams by researchers

Security vulnerabilities found in Microsoft Teams by researchers

OnePlus 15R review: A clear shift in what the R-series stands for

OnePlus 15R review: A clear shift in what the R-series stands for

POCO C85: A strong package with some rough edges

POCO C85: A strong package with some rough edges

Lenovo Legion 27Q10 Review: A serious gaming monitor under ₹20,000

Lenovo Legion 27Q10 Review: A serious gaming monitor under ₹20,000

Redmi 15C 5G Review: Xiaomi’s budget phone that just refuses to die in a day

Redmi 15C 5G Review: Xiaomi’s budget phone that just refuses to die in a day

Samsung Galaxy M17 5G Review: Best Budget Samsung Phone Under ₹15,000?

Samsung Galaxy M17 5G Review: Best Budget Samsung Phone Under ₹15,000?

ADVERTISEMENT

editorji-whatsApp

More videos

OnePlus 15R first look: OnePlus changes the R-series playbook

OnePlus 15R first look: OnePlus changes the R-series playbook

OnePlus Pad Go 2 First Look: Larger display, more polish, but does it work?

OnePlus Pad Go 2 First Look: Larger display, more polish, but does it work?

Realme Watch 5 Review: A budget smartwatch that gets the basics right

Realme Watch 5 Review: A budget smartwatch that gets the basics right

Realme P4x Review: Budget performer with a beast of a battery

Realme P4x Review: Budget performer with a beast of a battery

Nothing Phone 3a Community Edition ASMR Unboxing & First Look: For the fans, by the fans

Nothing Phone 3a Community Edition ASMR Unboxing & First Look: For the fans, by the fans

Comic Con Delhi 2025: Sony PlayStation Leads the Floor

Comic Con Delhi 2025: Sony PlayStation Leads the Floor

OnePlus marks 12 years in India with a new six-star lineup for the 15R reveal

OnePlus marks 12 years in India with a new six-star lineup for the 15R reveal

Vivo X300 Pro Review: Pro-grade cameras, fantastic performance, but is it truly unbeatable?

Vivo X300 Pro Review: Pro-grade cameras, fantastic performance, but is it truly unbeatable?

Realme Watch 5 First Look: Inside the factory where It’s Made in India

Realme Watch 5 First Look: Inside the factory where It’s Made in India

Vivo X300 Review: Compact flagship, powerful performance, but what about the cameras?

Vivo X300 Review: Compact flagship, powerful performance, but what about the cameras?

Editorji Technologies Pvt. Ltd. © 2022 All Rights Reserved.