Microsoft Teams fixes a security vulnerability that exploited GIFs to access a user's
#1
Information 
Quote:Apps like Microsoft Teams have seen a steady rise in popularity courtesy of the COVID-19 pandemic and the resultant social distancing. But they've had their fair share of privacy concerns too. Last month, security researchers at CyberArk uncovered a flaw in Microsoft Teams (desktop and web browser version both) that put an account and the associated computer's data at risk with the help of a GIF.
 
Succinctly, all the user had to do was view a specific GIF that they had received. Once this was done, in the background, a hacker could use a compromised subdomain to steal security tokens and mine the victim's data.
 
Concretely, the malicious GIF enclosed an 'src' attribute. When it was opened, the target browser would try to load the GIF and this would send the 'authtoken' cookie, which is used to authenticate the loading of images in domains across Skype and Teams, to the compromised sub-domain. This meant that the attacker would get their hands on the victim’s authtoken, allowing them to carve a pathway to scrape the victim’s data.
 
The bug was reported to Microsoft on March 23, but the issue has now been fixed in a recent update. CyberArk stated that it worked on the vulnerability with Microsoft Security Research Center under Coordinated Vulnerability Disclosure. So far, there is no evidence that suggests that the bug was exploited by cybercriminals.

Source: https://www.neowin.net/news/microsoft-te...users-data
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Intel shares Granite Rapids-WS Xeon 600 ...
Intel posts Xeon 6...harlan4096 — 09:49
Manjaro Linux 26.0.3 Build 260228
Manjaro Linux 26.0...harlan4096 — 08:20
K-Lite Codec Pack 19.5.0 / 19.5.4 Update
Changes in 19.5.4 ...harlan4096 — 08:19
JEDEC publishes UFS 5.0 spec with up to ...
KIOXIA starts samp...harlan4096 — 08:17
QOwnNotes
26.2.15  Fix Qt5 ...Kool — 07:30

[-]
Birthdays
Today's Birthdays
avatar (50)daadAmomo
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (43)slavrProck
avatar (45)Tyesharaike
avatar (49)TomeRerla
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (45)tukraNax
avatar (51)Claudestync
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu
avatar (41)ARYsahulatbazar

[-]
Online Staff
There are no staff members currently online.

>