Microsoft Teams Had a Vulnerability That Allowed Your Account to Be Hijacked With a GIF: Report

Microsoft said it worked with the researchers who found the threat, and fixed the issue.

Advertisement
By Vineet Washington | Updated: 30 April 2020 16:33 IST
Highlights
  • Microsoft Teams account takeover vulnerability has been spotted
  • Microsoft said it has fixed the issue
  • Teams users’s accounts could have been taken over using a malicious GIF

Microsoft Teams is a free to use video conferencing service

Microsoft Teams is among the popular video conferencing services and has seen a rise in users owing to the coronavirus pandemic. But, with the increase in user base, comes an increased security risk. A new analysis of Microsoft Teams by information security company CyberArk found that user accounts were vulnerable to takeovers just by sharing a malicious GIF. This vulnerability is associated to the temporary access token created by Microsoft Teams at various points and can affect both the Teams desktop or web browser versions. However, Microsoft said it has addressed the issue and taken steps to keep its customers safe.

Background for temporary access tokens

The vulnerability was spotted by CyberArk when it analysed how Microsoft Teams works. During the research, it was found that every time Teams is opened, the client creates a new temporary token or access token. Just like the initial access token, there are other tokens that are created as well for say for SharePoint, Outlook and other services. These tokens are then used to allow a user to see images or GIFs shared with them or by them. As these images are stored on Microsoft's servers, a token called “skype token” is created and can also be seen as a cookie called “skypetoken_asm.”

Vulnerability

The researchers noted that Teams makes sure that users will be able to see the content by establishing two cookies called “authtoken” and “skypetoken_asm.” Thus, if someone gets access to the authtoken, they can create a skype token. Stating that two of the sub-domains under Microsoft Teams namely, ‘aadsync-test.teams.microsoft.com' and ‘data-dev.teams.microsoft.com', were vulnerable to a subdomain takeover, CyberArk said that if an attacker can “force a user to visit the sub-domains”, the victim's browser will send a cookie to the attacker's server, which will allow the attacker to create a skype token. This will then give the attacker access to the victim's Teams account data.

Advertisement

 

By leveraging this vulnerability in Microsoft Teams, CyberArk stated that attackers could have used a malicious GIF to “scrape user's data and ultimately take over an organization's entire roster of Teams accounts.” It was noted that vulnerabilities like this have the ability to spread automatically and would affect every user who uses the Teams desktop or web browser version.

Microsoft's response

The analysis also pointed out that after working with Microsoft Security Research Center, the issue was fixed. According to ZDNet, Microsoft said, “We addressed the issue discussed in this blog and worked with the researcher under Coordinated Vulnerability Disclosure. While we have not seen any use of this technique in the wild, we have taken steps to keep our customers safe."


In 2020, will WhatsApp get the killer feature that every Indian is waiting for? Samsung Galaxy S20 in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week (Feb 16 - Feb 22): Know What to Watch This Weekend
  2. Realme P4 Lite With 6,300mAh Battery Launched at This Price in India
  3. WhatsApp's New Feature Allows New Members to View Past Group Messages
  4. First User Report of iPhone Air's C1X Modem Failure Surfaces Online
  5. Google Chrome Now Lets You Annotate PDFs, View Tabs in Split View
  6. Nothing Confirms the Upcoming Phone 4a Series Will Sport a Snapdragon Chip
  7. Vivo V70 Elite Review: Vivo's V-Series Goes 'Elite'
  8. Poco X8 Pro Series Display, Chipset, Battery Details Leak Online
  9. Meta Reportedly Plans Smartwatch Launch in 2026 With These Features
  10. Samsung Galaxy Buds 4 Leak Again as Dummy Units Surface Online
  1. Google Chrome Updated With Split View, Built-In PDF Markup Tools, and More Features
  2. Realme P4 Lite Launched in India With 6,300mAh Battery, 13-Megapixel Camera: Price, Specifications
  3. Samsung Galaxy Buds 4 Leak Again as Dummy Units Surface Online: Expected Price, Features
  4. Sony to Shut Down Demon's Souls Remake Developer Bluepoint Games in March
  5. Amazfit T-Rex Ultra 2 Launched With BioTracker 6.0 Sensor, 1.5-Inch AMOLED Display
  6. iPhone Air User Complains of C1X Modem Failure, Claims Mobile Diagnostics Suggests Hardware Issue
  7. Redmi Buds 8 Active Price, Design, Key Features Leaked Ahead of Anticipated Launch
  8. Samsung's One UI 8.5 Update Will Introduce Upgraded Bixby With Natural Voice Commands, Real-Time Web Access
  9. Poco X8 Pro and Poco X8 Pro Max to Feature 1.5K OLED Screens, 100W Charging Support, Tipster Claims
  10. WhatsApp Rolls Out Group Message History Feature for Easy Onboarding of New Members
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.