Microsoft Teams fixes funny Gifs cyber-attack flaw


A man laughs at something on his phone while working from home in this photoImage copyright
Getty Images

A security problem in Microsoft Teams meant cyber-attacks could be initiated via funny Gif images, researchers have revealed.

Like many chat apps, Teams lets colleagues send each other whimsical animated Gif images.

But CyberArk researchers discovered a problem that meant viewing a Gif could let hackers compromise an account and steal data.

Microsoft has since patched the security hole, researchers said.

The flaw involved a compromised subdomain serving up the malicious images.

All a user had to do was view the Gif to allow an attacker to scrape data from their account.

If left open, the flaw could have led to widespread data theft, ransomware attacks and corporate espionage, the team added.

Microsoft Teams, like many workplace collaboration tools, has seen huge growth in the past month, due to coronavirus lockdown rules.

This attack involves using a compromised subdomain to steal security tokens when a user loads an image – but the end user would just see the Gif sent to them, and nothing else.

“They will never know that he or she has been attacked – making this vulnerability… very dangerous,” the team said.

“It also demonstrates very nicely so-called zero-click attacks – my merely displaying the gif in this attack could potentially work, no clicking in dodgy links or opening booby-trapped documents.”

But Prof Woodward added that all software was bound to have security flaws occasionally.

“It’s a salutary tale of why you need to keep your software updated,” he said


Source link

Leave a Reply

Your email address will not be published.