There is a security flaw in Microsoft Teams that allows threat actors to log into other people's accounts, even if those accounts are protected by multi-factor authentication, researchers have claimed.
See also: GIFShell attack infects Microsoft Teams using GIFs

Cybersecurity analysts from Vectra say that the Teams desktop application for Windows, Linux , and Macstores user authentication tokens in clear text, without any locking to protect access. Anyone with local access to a system with Teams installed can steal these tokens and use to log in to accounts.
See also: Microsoft Teams: Fully optimized for Mac with M1 or M2 chip
"This attack does not require special permissions or advanced malware," said Vectra's Connor Peoples - Microsoft, on the other hand, says it is not currently interested in addressing the issue.
Active tokens
The problem lies in the fact that Microsoft Teams is an Electron application, running in browser windows. Since Electron does not have support for encryption or protected file locations by default, it is somewhat easier to use, but also risky from a data protection. Deeper analysis revealed that the tokens were not stored accidentally or as part of a previous data dump.
“Upon examination, it was determined that these access tokens were active and not a random dump of a previous error. These access tokens gave us access to the Outlook and Skype,” Vectra explained. In addition, the “cookies” folder also contained tokens, account information, session data, and other valuable information.
But Microsoft downplayed the whole issue, saying it's not that serious and doesn't meet the criteria for a fix.
In a statement sent to BleepingComputer, Microsoft said: "The technique described does not meet our line of immediate service, as it requires an attacker to first gain access to a target network. We appreciate Vectra Protect's cooperation in identifying and responsibly disclosing this issue and will consider addressing it in a future product release."

Vectra, on the other hand, disagrees, and to prove its point, it developed an exploit that abuses an API call, allowing a user to send messages to themselves. By reading the cookies database via the SQLite engine, the exploit was able to obtain the authentication tokens in a message.
See also: Microsoft Teams for web just got new features
If you're worried about your business tokens being stolen, you should switch to the browser version of the Teams client, Vectra suggests. Linux users should also migrate to a different collaboration platform .
Information source: techradar.com
