Trustwave, a Top 200 MSSP, has discovered a Microsoft Teams Updater vulnerability that enables cybercriminals to use the "Living Off the Land" technique to download a binary or payload onto a victim's computer.Microsoft previously provided a Teams patch to restrict Updater's ability to update via a URL, Trustwave indicated. However, cybercriminals can bypass this restriction by setting up a remote Server Message Block (SMB) shared folder.To exploit the Teams Updater vulnerability, cybercriminals must access a network file in an end-user's open shared folders, Trustwave noted. Then, they can access a payload from that folder and apply it to a victim's computer.
Also, Trustwave is encouraging organizations to establish a policy relating to Teams updates. This policy should require organizations to allow authorized IT professionals only to update Teams across all departments.
How to Combat the Microsoft Teams Updater Vulnerability
Trustwave offered the following recommendations to help organizations combat the Teams Updater vulnerability:- Use endpoint detection and response (EDR) solutions and find "update.exe" command lines for suspicious connections.
- Search for squirrel.exe executables and investigate the file size; this enables end-users to distinguish trojan squirrels from the legitimate squirrel.exe.
- Evaluate outgoing SMB connections from Teams or filter SMB connections at the perimeter.
- Identify any security exclusions on Microsoft Teams packages and review any applied changes.
- Install Microsoft Teams under the "Program Files" folder; this can be carried out via Group policy.
- Disable any update mechanisms.
