Home United States USA — software Microsoft Teams might have a few serious security issues

Microsoft Teams might have a few serious security issues

169
0
SHARE

Security researchers have discovered four vulnerabilities in Microsoft’s link preview feature in Teams.
Security researchers have discovered four separate vulnerabilities in Microsoft Teams that could be exploited by an attacker to spoof link previews, leak IP addresses and even access the software giant’s internal services. These discoveries were made by researchers at Positive Security who “stumbled upon” them while looking for a way to bypass the Same-Origin Policy (SOP) in Teams and Electron according to a new blog post. For those unfamiliar, SOP is a security mechanism found in browsers that helps stop websites from attacking one another. During their investigation into the matter, the researchers found that they could bypass the SOP in Teams by abusing the link preview feature in Microsoft’s video conferencing software by allowing the client to generate a link preview for the target page and then using either summary text or optical character recognition ( OCR) on the preview image to extract information.

Continue reading...