{"id":460748,"date":"2022-09-15T13:29:07","date_gmt":"2022-09-15T11:29:07","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=460748"},"modified":"2022-09-15T13:30:40","modified_gmt":"2022-09-15T11:30:40","slug":"serious-security-flaw-in-microsoft-teams","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/460748-serious-security-flaw-in-microsoft-teams.html","title":{"rendered":"Serious security flaw in Microsoft Teams"},"content":{"rendered":"<p>Cybersecurity firm Vectra has uncovered a severe security vulnerability in the desktop apps of Microsoft Teams on Windows, Mac, and Linux.<\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-teams-stores-auth-tokens-as-cleartext-in-windows-linux-macs\/\" target=\"_blank\" rel=\"noopener\"><strong>BleepingComputer reports<\/strong><\/a> that Vectra&#8217;s security researchers found that the apps store user authentication tokens on-system in plaintext without restricting access to them.<\/p>\n<p>Malicious actors could steal the tokens and use them to log into a target&#8217;s account.<\/p>\n<p>&#8220;This attack does not require special permissions or advanced malware to get away with major internal damage,&#8221; said Vectra&#8217;s Connor Peoples.<\/p>\n<p>Peoples said the exploit could be used to take control of critical seats within a company\u2014 like a company&#8217;s head of engineering, CEO, or CFO \u2014 to convince users to perform tasks that could damage the organisation.<\/p>\n<p>The desktop app runs on the widely-used open-source Electron framework, which was <a href=\"https:\/\/mybroadband.co.za\/news\/security\/456321-serious-security-flaws-discovered-in-software-behind-microsoft-teams-and-discord.html\" target=\"_blank\" rel=\"noopener\"><strong>previously also found<\/strong><\/a> to open up serious remote control vulnerabilities in Teams and Discord apps.<\/p>\n<p>Electron offers no encryption support or protected file locations unless the developer is willing to put in extensive work to customise their app with the capability.<\/p>\n<p>Vectra had analysed Microsoft Teams while attempting to remove deactivated accounts from client apps and stumbled upon an ldb file with the access tokens in plaintext.<\/p>\n<p>&#8220;Upon review, it was determined that these access tokens were active and not an accidental dump of a previous error. These access tokens gave us access to the Outlook and Skype APIs,&#8221; Peoples explained.<\/p>\n<p>Fortunately, an attacker would require local access to a system to gain access to the tokens.<\/p>\n<p>A Microsoft spokesperson told BleepingComputer that the technique used to exploit the vulnerability did not meet its bar for immediate servicing as it requires an attacker to first gain access to a target network.<\/p>\n<p>&#8220;We appreciate Vectra Protect&#8217;s partnership in identifying and responsibly disclosing this issue and will consider addressing in a future product release,&#8221; the spokesperson said.<\/p>\n<p>Vectra said since a patch was unlikely in the immediate future, it recommended that users switch to the browser-based version of the Teams client as a precautionary measure.<\/p>\n<hr \/>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/software\/458639-former-microsoft-design-bigwig-roasts-windows-11-start-menu.html\" rel=\"bookmark\">Former Microsoft design bigwig roasts Windows 11 Start Menu<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>The widely-used Electron framework has another major vulnerability in the Microsoft Teams desktop app.<\/p>\n","protected":false},"author":341042,"featured_media":448986,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[80561,123,39614,81400],"class_list":["post-460748","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-electron","tag-microsoft","tag-microsoft-teams","tag-vectra"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/460748"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341042"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=460748"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/460748\/revisions"}],"predecessor-version":[{"id":460808,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/460748\/revisions\/460808"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/448986"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=460748"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=460748"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=460748"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}