Highlights

  • Team of researchers finds 4 vulnerabilities in Microsoft Teams
  • Microsoft Teams issues could compromise information, cause app crashes
  • Positive Security disclosed Teams issues to Microsoft in March 2021

Latest news

OnePlus 15R first look: OnePlus changes the R-series playbook

OnePlus 15R first look: OnePlus changes the R-series playbook

India's retail inflation rises to 0.71% in November

India's retail inflation rises to 0.71% in November

Cabinet approves CoalSETU window for auction of coal to boost industrial use and export

Cabinet approves CoalSETU window for auction of coal to boost industrial use and export

Cabinet approves Minimum Support Price for Copra for 2026 season

Cabinet approves Minimum Support Price for Copra for 2026 season

Fire never left: Vinesh Phogat comes out of retirement, targets LA Olympics

Fire never left: Vinesh Phogat comes out of retirement, targets LA Olympics

Flexible office segment in India set to grow faster, over 25% annually by 2027: Report

Flexible office segment in India set to grow faster, over 25% annually by 2027: Report

Rahul Gandhi flags issue of air pollution, seeks discussion in Lok Sabha

Rahul Gandhi flags issue of air pollution, seeks discussion in Lok Sabha

Japan lifts tsunami warning after magnitude 6.7 quake

Japan lifts tsunami warning after magnitude 6.7 quake

Security vulnerabilities found in Microsoft Teams by researchers

A team of researchers from Positive Security found four vulnerabilities in Microsoft Teams, only one of which has been patched so far.

Security vulnerabilities found in Microsoft Teams by researchers

A team of researchers from Positive Security found four vulnerabilities in Microsoft Teams, they announced in a blog post. A total of four vulnerabilities were found, which could allow an attacker to spoof link previews, access internal Microsoft services, leak IP addresses, and DDoS the teams App on Android.

The team reportedly found the issues while researching the URL preview feature in Teams, Positive Security co-founder Fabian Bräunlein said.

Four vulnerabilities found in Microsoft Teams

One of the vulnerabilities is a Server-Side Request Forgery issue, which could leak information such as the response time, code, size, and open graph data. Another is a spoofing attack, which could open a different link than what was expected by the user when clicking a preview link, leading to a possible phishing attack.

A third vulnerability could allow leaking a user's IP address and user agent data by sending a message with a specially crafted link preview on Android.

The fourth, and potentially most serious vulnerability, allows a malicious attacker to crash the Teams app on Android completely, by sending a message with an invalid preview link. Opening the chat or conversation with the bad link will then repeatedly crash the Teams app.

Also Read: Apple iPhone 13 to be made in India: all you need to know

Microsoft issues fix for one issue

Positive Security say that they disclosed these vulnerabilities to Microsoft on March 10, 2021. However, they claim that Microsoft has only patched one of the four mentioned issues, concerning the IP leak on Android.

Bräunlein said that the DDoS issue could ‘become annoying’ for some users, but only the link spoofing vulnerability is likely to be used in serious attacks.

ADVERTISEMENT

Up Next

Security vulnerabilities found in Microsoft Teams by researchers

Security vulnerabilities found in Microsoft Teams by researchers

OnePlus 15R first look: OnePlus changes the R-series playbook

OnePlus 15R first look: OnePlus changes the R-series playbook

OnePlus Pad Go 2 First Look: Larger display, more polish, but does it work?

OnePlus Pad Go 2 First Look: Larger display, more polish, but does it work?

Realme Watch 5 Review: A budget smartwatch that gets the basics right

Realme Watch 5 Review: A budget smartwatch that gets the basics right

Realme P4x Review: Budget performer with a beast of a battery

Realme P4x Review: Budget performer with a beast of a battery

Nothing Phone 3a Community Edition ASMR Unboxing & First Look: For the fans, by the fans

Nothing Phone 3a Community Edition ASMR Unboxing & First Look: For the fans, by the fans

ADVERTISEMENT

editorji-whatsApp

More videos

Comic Con Delhi 2025: Sony PlayStation Leads the Floor

Comic Con Delhi 2025: Sony PlayStation Leads the Floor

OnePlus marks 12 years in India with a new six-star lineup for the 15R reveal

OnePlus marks 12 years in India with a new six-star lineup for the 15R reveal

Vivo X300 Pro Review: Pro-grade cameras, fantastic performance, but is it truly unbeatable?

Vivo X300 Pro Review: Pro-grade cameras, fantastic performance, but is it truly unbeatable?

Realme Watch 5 First Look: Inside the factory where It’s Made in India

Realme Watch 5 First Look: Inside the factory where It’s Made in India

Vivo X300 Review: Compact flagship, powerful performance, but what about the cameras?

Vivo X300 Review: Compact flagship, powerful performance, but what about the cameras?

Nothing Phone 3a Lite Review: Easy to like, but is it good value for money?

Nothing Phone 3a Lite Review: Easy to like, but is it good value for money?

iQOO 15 Review: A premium leap that finally puts iQOO in the top tier

iQOO 15 Review: A premium leap that finally puts iQOO in the top tier

Realme GT 8 Pro Dream Edition: Premium or Just Racing Paint? Full Review  

Realme GT 8 Pro Dream Edition: Premium or Just Racing Paint? Full Review  

Blaupunkt 65-inch Google Mini QD TV Review: The Surprise Package of 2025?

Blaupunkt 65-inch Google Mini QD TV Review: The Surprise Package of 2025?

Oppo Find X9 Pro Review: Massive Battery, Pro Cameras, Big Price — Worth It?

Oppo Find X9 Pro Review: Massive Battery, Pro Cameras, Big Price — Worth It?

Editorji Technologies Pvt. Ltd. © 2022 All Rights Reserved.