Connect with us

Technology

Microsoft Teams might have a few serious security issues

Published

on

Microsoft Teams might have a few serious security issues

Security researchers have discovered four separate vulnerabilities in Microsoft Teams. Attackers can use these vulnerabilities to spoof link previews, leak IP addresses, and even access the software giant’s internal services.

According to a new blog post, these findings were “stumbled upon” by Positive Security researchers while looking for a way to bypass the Same Origin Policy (SOP) in Teams and Electron. For those who are unfamiliar, SOP is a security mechanism in the browser that can help prevent websites from attacking each other.

During the investigation of this matter, the researchers found that they could bypass the SOP in Teams by abusing the link preview feature in the Microsoft video conferencing software, allowing the client to generate link previews for the target page, and then use summary text or optical preview images On the character recognition (OCR) to extract information.

However, while performing this operation, Positive Security co-founder Fabian Bräunlein discovered other unrelated vulnerabilities in the implementation of this feature. Microsoft Teams vulnerability
Of the four vulnerabilities discovered by Bräunlein in Teams, two can be used on any device and allow server-side request forgery (SSRF) and spoofing, while the other two only affect Android smartphones and can be exploited to leak IP addresses and achieve Denial of service (DOS).

Advertisement

By exploiting SSRF vulnerabilities, researchers were able to leak information from Microsoft’s local network. At the same time, spoofing vulnerabilities can be used to increase the effectiveness of phishing attacks or hide malicious links.

The DOS error is particularly worrying because an attacker can send a message to the user that contains a link preview with an invalid preview link target (for example, “boom” instead of “https://…”), thereby causing the Teams application The program crashes Android. Unfortunately, when trying to open a chat or channel with malicious messages, the app will continue to crash.

Positive Security disclosed its findings to Microsoft responsibly through its bug bounty program on March 10. However, since then, the software giant has only patched the IP address leak vulnerability in the Android version of Teams. Now Positive Security has publicly disclosed its findings. Although Microsoft told researchers that they would not pose a direct threat to its users, it may have to patch the remaining three vulnerabilities.

Complete News Source : techradar.pro

Advertisement

Technology

Surfaces of the Motorola Edge 50 Ultra with Snapdragon 8S Gen 3

Published

on

By

Surfaces of the Motorola Edge 50 Ultra with Snapdragon 8S Gen 3

Early this week, renders of the Edge 50 Fusion appeared, and Motorola has previously stated that the Edge 50 Pro will ship on April 3. The highest-end smartphone in the Edge 50 series, the Edge 50 Ultra, has now been shown in renders.

The phone is depicted in the renderings in peach fuzz and black with a vegan leather finish, while sisal, a beige color, will have a brushed surface. As opposed to the Snapdragon 7 Gen 3 in the Pro variant and the Snapdragon 6 Gen 1 in the Edge 50 Fusion, the phone is reportedly powered by the Snapdragon 8s Gen 3 SoC.

A 50MP primary camera, an ultra-wide camera, and a periscope telephoto camera with a 5x optical zoom are all included in the Motorola Edge 50 Ultra’s feature set. Additionally, there is a triple LED flash on the right side and a laser autofocus feature above the periscope lens.

Although the phone’s display, battery, and charging specifications are yet unknown, the Edge 50 Pro is said to include 12GB of RAM and support both 50W and 125W wired and wireless charging.

Advertisement

It is anticipated that this will launch as the Motorola X50 Ultra in China. It is unclear if the India launch may be expected on the same day as the rest of the Edge 50 series phones, even if this is scheduled to go official on April 3.

Group Media Publications
Entertainment News Platforms – anyflix.in      
Construction Infrastructure and Mining News Platform – https://cimreviews.com/
General News Platform – https://ihtlive.com/
Podcast Platforms – https://anyfm.in

Continue Reading
Anyskill-ads

Facebook

[the_ad id="55117"]

Trending