Advisory 29

Impact: High

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Office of the Chief Information Officer (OGCIO) provide the following advisory.


On June 06th, 2023, CERT Vanuatu discovered on a number of reputable sources of a tool called “TeamsPhisher” which was developed by Security experts at the US Navy has recently discovered a flaw in Microsoft Teams.  

What is it?

The “TeamPhishing” tool exploits Microsoft Teams and allow attackers to easily go around Microsoft Teams’ file-sending restraints to deliver malware from an external account.

References

  1. https://www-bleepingcomputer-com.cdn.ampproject.org/c/s/www.bleepingcomputer.com/news/security/new-tool-exploits-microsoft-teams-bug-to-send-malware-to-users/amp/?fbclid=IwAR0opJGRwWJtR58_no_V2DsCCXFN7eH_0BBm8QfiXnI8_UwoCWbQfTrXKfE
  2. https://labs.jumpsec.com/advisory-idor-in-microsoft-teams-allows-for-external-tenants-to-introduce-malware/