
Microsoft has fixed security issues in Microsoft Teams that hackers could use to take control of accounts user , with the help of a .GIF file .
On Monday, security researchers from CyberArk said that a “subdomain takeover vulnerability, combined with a malicious .GIF file, could be used to “ exfiltrate data a user’s and ultimately take control of all of Microsoft Teams accounts.”
The researchers said the security issues affected Microsoft Teams on both the desktop and web browser versions.
Microsoft's communication platform is used by many people, especially during this time due to COVID-19. Microsoft Teams is also used by many businesses, allowing the sharing of corporate data and, therefore, an attractive target for hackers.
CyberArk researchers studied the platform and found that every time the application is opened, the Teams client generates a new temporary access token. The problem had to do with the way Microsoft handled these tokens, which essentially prove that a legitimate user is accessing the Teams account.
Microsoft manages these tokens on its server, at teams.microsoft.com or any subdomain under that address. CyberArk found that two of these subdomains, aadsync-test.teams.microsoft.com and data-dev.teams.microsoft.com, were vulnerable to a subdomain takeover vulnerability.
“If an attacker can somehow force a user to visit the compromised subdomains, the victim’s browser will send the tokens to the attacker’s server, and the attacker can then generate another token, the Skype token,” the researchers said. “After all this, the attacker can steal the victim’s Microsoft Teams account data.”
However, the attack is complicated, as the attacker must issue a certificate for the compromised subdomains.
As the subdomains were already vulnerable, this challenge was overcome, and by sending either a malicious link to the subdomain or a .GIF file to Teams, the required token could be generated for the attacker to gain access. Simply viewing the GIF is enough, so more Microsoft Teams users can be affected in a single attack.

CyberArk has released proof-of-concept (PoC) code that shows how the attacks could be carried out , along with a script that could be used to steal Teams conversations.

“COVID-19 has forced many companies to shift to remote work, leading to a significant increase in the number of users using Teams or other platforms like it,” CyberArk says. “Even if an attacker doesn’t gather much information from a Teams account, they could use the account to ‘cross’ the entire organization.”
The researchers worked with the Microsoft Security Response Center (MSRC) under the Coordinated Vulnerability Disclosure (CVD) to report their findings.
CyberArk reported the vulnerability on March 23. On the same day, Microsoft fixed the incorrect DNS settings of two subdomains that allowed attackers to take control of Teams accounts. On April 20, the company also released a patch to mitigate the risk of similar errors.
A Microsoft spokesperson said: "We addressed the issue discussed in this blog and worked with researchers as part of the Coordinated Vulnerability Disclosure. While we have not seen any exploitation of this technique, we have taken steps to keep our customers safe.".
