Microsoft Teams bug allowing phishing unpatched since March

Share on linkedin
Share on facebook
Share on twitter

Microsoft said it won’t fix or is delaying patches for several security flaws impacting Microsoft Team’s link preview feature reported since March 2021.

Bräunlein reported the four flaws to the Microsoft Security Response Center, which investigates vulnerability reports concerning Microsoft products and services.

“The vulnerabilities allow accessing internal Microsoft services, spoofing the link preview, and, for Android users, leaking their IP address and DoS’ing their Teams app/channels,” the researcher said.

The URL preview spoofing bug that threat actors could use for phishing attacks or camouflage malicious links was tagged as not posing any danger to Teams users.

The company’s decision not to address the spoofing bug which could be abused in phishing campaigns is partially explained by Teams also using Defender for Office 365 Safe Links protection to safeguard users from URL-based phishing attacks since July.

While Safe Links protection is available to all Teams users and works for links shared across conversations, group chats, and Teams channels, it still needs to be enabled by setting up a Safe Links policy in the Microsoft 365 Defender portal.

Stay on Top of Cyber Threats!

Subscribe to our monthly bulletin to stay updated on major cybersecurity risks.

Follow us on Socials:

Recent Cybersecurity News

483 accounts compromised in $34 million hack has confirmed that a multi-million dollar cyber attack led to the compromise...
Read The Article

CISA urges US orgs to prepare for data-wiping cyberattacks

The Cybersecurity and Infrastructure Security Agency urges U.S. organizations to strengthen their cybersecurity...
Read The Article

Cybercriminals Actively Target VMware vSphere with Cryptominers

Organizations running sophisticated virtual networks with VMware's vSphere service are actively being targeted...
Read The Article

Contact a Specialist

Discover why 1,000+ organizations trust our expertise to improve their cybersecurity.

Stay Updated on Cyber Risks!

Subscribe to the Vumetric Monthly Bulletin to keep up with breaking news in the cybersecurity industry.