Security News > 2020 > August > Microsoft Teams Patch Bypass Allows RCE
![Microsoft Teams Patch Bypass Allows RCE](/static/build/img/news/microsoft-teams-patch-bypass-allows-rce.jpg)
Adding insult to injury, researchers have recently discovered a workaround for a previous patch issued for Microsoft Teams, that would allow a malicious actor to use the service's updater function to download any binary or malicious payload. Essentially, bad actors could hide in Microsoft Teams updater traffic, which has lately been voluminous.
While Microsoft tried to cut off this vector as a conduit for remote code execution by restricting the ability to update Teams via a URL, it was not a complete fix, the researcher explained.
"The updater allows local connections via a share or local folder for product updates," Jayapaul said.
Trustwave has published a proof-of-concept attack that uses Microsoft Teams Updater to download a payload - using known, common software called Samba to carry out remote downloading.
"After a successful setup, I initiated the command execution, downloaded remote payload and executed directly from Microsoft Teams Updater, 'Update.exe,'" the researcher explained.
News URL
https://threatpost.com/microsoft-teams-patch-bypass-rce/158043/
Related news
- Microsoft June 2024 Patch Tuesday fixes 51 flaws, 18 RCEs (source)
- Exploit for critical Progress Telerik auth bypass released, patch now (source)
- Zyxel issues emergency RCE patch for end-of-life NAS devices (source)
- June 2024 Patch Tuesday forecast: Multiple announcements from Microsoft (source)
- Week in review: Atlassian Confluence RCE PoC, new Kali Linux, Patch Tuesday forecast (source)
- Exploit for critical Veeam auth bypass available, patch now (source)
- Microsoft fixes RCE vulnerabilities in MSMQ, Outlook (CVE-2024-30080, CVE-2024-30103) (source)
- Exploit for Veeam Recovery Orchestrator auth bypass available, patch now (source)
- VMware fixes critical vCenter RCE vulnerability, patch now (source)
- Microsoft July 2024 Patch Tuesday fixes 142 flaws, 4 zero-days (source)