MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
microsoft
Recherche

Microsoft Teams Stores Auth Tokens As Cleartext In Windows, Linux, Macs

jeudi 15 septembre 2022, 01:20 , par Slashdot
Security analysts have found a severe security vulnerability in the desktop app for Microsoft Teams that gives threat actors access to authentication tokens and accounts with multi-factor authentication (MFA) turned on. BleepingComputer reports: 'This attack does not require special permissions or advanced malware to get away with major internal damage,' Connor Peoples at cybersecurity company Vectra explains in a report this week. The researcher adds that by taking 'control of critical seats -- like a company's Head of Engineering, CEO, or CFO -- attackers can convince users to perform tasks damaging to the organization.' Vectra researchers discovered the problem in August 2022 and reported it to Microsoft. However, Microsoft did not agree on the severity of the issue and said that it doesn't meet the criteria for patching.

With a patch unlikely to be released, Vectra's recommendation is for users to switch to the browser version of the Microsoft Teams client. By using Microsoft Edge to load the app, users benefit from additional protections against token leaks. The researchers advise Linux users to move to a different collaboration suite, especially since Microsoft announced plans to stop supporting the app for the platform by December.

Read more of this story at Slashdot.
https://it.slashdot.org/story/22/09/14/1939242/microsoft-teams-stores-auth-tokens-as-cleartext-in-wi...
News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Date Actuelle
ven. 19 avril - 18:54 CEST