Skip to main content

This Microsoft Teams exploit could leave your account vulnerable

According to analysts from cybersecurity company Vectra, there’s a massive vulnerability within Microsoft Teams, and countless users could potentially be affected if hackers gets their hands on it.

The program has a flaw that makes it possible for attackers to steal the login credentials of users and log into their accounts. Unfortunately, Microsoft is not planning to patch this right now, so read on to make sure you’re staying safe from this unexpected Microsoft Teams issue.

A video call in Microsoft Teams is displayed on a laptop.
Image used with permission by copyright holder

This flaw, first discovered in August 2022, is pretty severe, but it’s also not too easy to execute. It applies to desktop versions of the Microsoft Teams software (so not the browser version) and affects users on Windows, Linux, and Mac.

Recommended Videos

It all comes down to the way Teams stores user authentication tokens — in clear text, without any extra protection. That would be disastrous if it didn’t rely on one key factor: An attacker needs to have local access to the system where Microsoft Teams is installed.

Assuming that an attacker does have local access to the network, they could steal the authentication tokens and log into the victim’s account.

Connor Peoples, a researcher from Vectra, said that the threat lies deeper than just one account being compromised; it allows the attacker to hijack accounts that could potentially disrupt the operations of a whole organization.

“[Taking] control of critical seats — like a company’s Head of Engineering, CEO, or CFO — attackers can convince users to perform tasks damaging to the organization,” said Peoples in the report.

How does this all work? Bleeping Computer explained it in greater detail, but the short story is that Microsoft Teams is an Electron app and comes with all the elements required by any regular webpage, such as cookies and session strings. Electron doesn’t support file encryption or establishing protected locations, which is why the user credentials are not being protected as they should be.

During its research, Vectra found a file with access to user tokens in clear text. “Upon review, it was determined that these access tokens were active and not an accidental dump of a previous error. These access tokens gave us access to the Outlook and Skype APIs,” the company’s report said.

Even more data was found upon further research, including valid authentication tokens and account information. Vectra also found a way to exploit the app and was able to receive the tokens in its own chat window.

Man uses Microsoft Teams on a laptop in order to video chat.
Image used with permission by copyright holder

It’s concerning that this vulnerability is currently out there, but Microsoft doesn’t consider it a large enough threat to work on patching it as a priority. A Microsoft spokesperson told Bleeping Computer: “The technique described does not meet our bar for immediate servicing as it requires an attacker to first gain access to a target network. We appreciate Vectra Protect’s partnership in identifying and responsibly disclosing this issue and will consider addressing it in a future product release.”

In the meantime, if you’re worried about the security of your Teams account, a good idea is to switch to the browser version of Teams instead of the desktop client. Linux users, however, are advised to simply switch to a different app — especially because Microsoft is planning to stop supporting the Linux version of Teams by the end of this year.

Monica J. White
Monica is a computing writer at Digital Trends, focusing on PC hardware. Since joining the team in 2021, Monica has written…
Microsoft just made Teams even more of a hassle to use
A Home screen in Microsoft Teams showing the different Communities to choose from.

In a Microsoft support article, the software giant says that starting in April 2025, Microsoft Teams will no longer support sending or receiving SMS from Android devices. This change pushes users to switch to the Phone Link app for SMS messaging.

If you attempt to send an SMS using Teams, you'll be greeted with an alert notifying you of the change. The SMS feature is one of the lesser-known features, and you may not have even known it existed, but Microsoft will soon remove it from Teams. For now, you can still view SMS messages under Recent and send texts, but this feature will soon be removed. Currently, the "Link your phone" feature lets you manage your text messages without having to switch to another app, thus making you go through fewer steps.

Read more
Microsoft 365 apps help keep your files safe with OneDrive backup
Microsoft OneDrive files can sync between a PC and a phone.

Microsoft 365 apps will encourage users to back up their files to OneDrive, as announced in a new Message Center entry, to improve data security. Microsoft will display a prompt across Word, Excel, and PowerPoint in the following months to prevent data loss and ensure users can access their important files seamlessly.

Microsoft will begin showing these prompts in mid-March 2025, encouraging users to sign up for the OneDrive Known Folder Move (KFM). The public preview will last until early April 2025 but will generally be available by May 2025. What is KFM? It's a feature in OneDrive that lets you sync and back up your important local folders, such as Desktop or Documents. Afterward, you can easily access your files across various devices.

Read more
I tried the free version of Microsoft Office. All I got was ads and anxiety
Running the ad-supported free version of Microsoft PowerPoint on a laptop.

Microsoft is testing a new version of its Office app bundle that is free to use, but you’ll have to watch ads. Usability is rather subjective here, because even the most basic features are locked and greyed out.

These free office apps, of which there are only three, will be available only for a limited span. And that too, in a select few markets. Moreover, Microsoft warns that it can discontinue these free Word, Excel, and PowerPoint desktops at nay day of its choosing.

Read more