Important vulnerabilities were found in the popular corporate messenger Microsoft Teams. This is another reminder that public services do not provide security guarantees in principle.
German cybersecurity group Positive Security has released four vulnerabilities in Microsoft Teams. It follows from the message that the developer was notified about them back in March, notes Kommersant . Moreover, Microsoft underpaid for the discovery of one critical vulnerability and did not fix the rest, the company claims.
The most obvious vulnerability is the ability to spoof the link preview and take the user to a phishing site or hide a malicious link. In addition, the messenger on the Android platform allows third-party agents to obtain the user's IP address and service information.
Microsoft told Kommersant that they have studied all four vulnerabilities and "they do not pose an immediate threat that requires fixes in the security system." And the leak of IP addresses on Android is closed.
Microsoft Teams is the fourth most popular platform among messengers and the fifth among video conferencing services among Russian corporate users (according to TrueConf, 6% and 9%, respectively). Originally an enterprise product, it is considered to be more secure than leading WhatsApp or Zoom.
The biggest threat of these vulnerabilities is the substitution of previews, Kommersant quotes Boris Larin, senior researcher of information security threats at Kaspersky Lab: “As a result, insufficiently attentive users can become victims, for example, of a phishing attack.”
In terms of significance and scope, the discovered vulnerabilities cannot be compared with the Apache Log4j disaster, which we talked about in the tech newsletter. Once they go public, Microsoft will have to shut them down, but as always, the question remains how many security holes are left. In a broad sense, this once again demonstrates that only standalone video services and instant messengers within the company can be truly secure. However, they require significant costs and qualified IT specialists, which are lacking in Russia .