Security News > 2020 > April > Microsoft Teams Vulnerability Exposed Organizations to Attacks

Microsoft Teams Vulnerability Exposed Organizations to Attacks
2020-04-27 09:47

The attacker can use this method to read the user's Teams messages, send messages on their behalf, create groups, add or remove users from a group, and change group permissions.

The entire attack can be automated, allowing malicious actors to spread through an organization like a worm by using compromised accounts to send the malicious GIF to other Teams users.

The cybersecurity firm told SecurityWeek that it believes the attack still works if someone is able to find Teams subdomains that can be hijacked.

In order to launch an attack such as the one described by CyberArk, the attacker also somehow needs to find a way to obtain access to a Teams account from which they can start sending malicious links or GIFs in order to spread within an organization.

If an attacker can convince the target to invite them to a job interview on Teams.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/TP9DBGuqBxA/microsoft-teams-vulnerability-exposed-organizations-attacks

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 480 75 2308 5127 264 7774