More

    A key Microsoft OneDrive feature has a worrying security flaw which could expose user data




    • Researchers found a flaw in Microsoft OneDrive File Picker
    • The flaw stems in the lack of fine-grained OAuth permissions
    • Microsoft acknowledges the flaw, but hasn’t fixed it yet

    A vulnerability in Microsoft’s OneDrive File Picker has been found which could allow threat actors to access people’s entire cloud archives, experts have warned.

    Security researchers Oasis discovered the flaw and reported it to Microsoft, noting the problem lies in excessive permissions that File Picker asks for – including read access to the entire drive. The tool asks for these permissions since the OAuth scopes for OneDrive aren’t fine-grained.

    https://cdn.mos.cms.futurecdn.net/JucJ4RrRuxQynsKUY6Yunj.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img