Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Microsoft Teams bug allows malware delivery from external accounts

  • June 26, 2023
Total
0
Shares
0
0
0


Microsoft Teams has a vulnerability that could see it being abused as a vector for delivering malware.

Security researchers at Jumpsec discovered a way to use the video conferencing software to inject malware into an organization’s network from a Teams account that is outside of the organization in question.

Using default configurations, the attack leverages the ability of an organization’s Microsoft Teams client to accept communications from ‘external tenants’ – those using Teams accounts from outside the company.

External communications

The Jumpsec report notes that while this exploit can be used to perpetrate social engineering and phishing attacks, it can also be used to send malware payloads to another inbox, despite Teams having protections to block files coming from external tenants.

The researchers found a way to bypass these restrictions, by altering the recipient ID both internally and externally in the POST request of a message, tricking Teams into thinking an external account is actually internal. 

During their tests, the researchers were able to successfully deliver a command and control payload into another organization’s inbox, as part of a covert operation. 

There is no need to bother with crafting a convincing phishing message to lure the victim, and if the threat actor were to register a domain similar to the target’s, then it may fool workers into thinking the link came from within the company, and therefore safe to download. 

After reporting the exploit to Microsoft, the tech giant responded that “it does not meet the bar for immediate servicing,” signifying the relatively low risk it thinks it poses. It has not yet confirmed when it will likely provide a patch. 

Communication with external tenants can be disabled by navigating to the Microsoft Teams Admin Center and then to External Access. If you do not wish to block all external communications, then you can choose to communicate with trusted domains only by adding them to the allow list. 

The researchers also submitted their findings to the Microsoft Teams feedback portal, where users can up-vote the post in the hope of pressing Microsoft to attend to the issue quicker. 


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

Amazon wants to turn small shops into delivery partners

  • June 26, 2023
View Post
Next Article
  • News

An A.I. Diagnosis Can Wait. Just Eliminate ‘Pajama Time.’

  • June 26, 2023
View Post
You May Also Like
View Post
  • News

Asus sells the largest microLED monitor ever for a cool $200,000 — but it’s only 4K and a low refresh rate

  • September 21, 2023
View Post
  • News

Facebook now lets you create alt accounts for better privacy and organization

  • September 21, 2023
View Post
  • News

The world’s most famous magician invests in data storage startup that wants to send 100GB disks to the Moon for future humanoids

  • September 21, 2023
View Post
  • News

YouTube reveals powerful new AI tools for content creators – and we’re scared, frankly

  • September 21, 2023
View Post
  • News

CEO of DuckDuckGo Testifies in Google Case

  • September 21, 2023
View Post
  • News

Windows Copilot might be the biggest change Microsoft has ever made to its long-running OS

  • September 21, 2023
View Post
  • News

Despite general investment downturn AI sees surge in spending, survey shows

  • September 21, 2023
View Post
  • News

Everything Microsoft announced at its 2023 Surface Event

  • September 21, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.