A Remote Code Execution (RCE) bug has been found in Microsoft Teams that can compromise a computer with no user interaction required. The vulnerability was discovered and submitted to Microsoft by Evolution Gaming engineer Oskars Vegeris, and it has been patched in the latest update to Teams. This bug allows adversaries to execute arbitrary code by merely sending a message to a targeted Teams user. This cross-platform RCE bug takes advantage of a Cross Site Scripting (XSS) flaw present in the Teams “@mentions” functionality, coupled with a JavaScript based RCE payload. By viewing this message, the attack is triggered and allows the attacker to execute code in the context of the intended victim.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security