Microsoft Teams susceptible to malicious GIF, says CyberArk Labs


By Amy Sarcevic
Wednesday, 29 April, 2020

Microsoft Teams susceptible to malicious GIF, says CyberArk Labs

New research from CyberArk Labs has uncovered a major technical vulnerability with popular videoconferencing tool Microsoft Teams.

Penetration testers found that, via the “subdomain takeover vulnerability”, attackers could send malicious GIFs and siphon all data associated with a user’s account.

The malicious file could then spread to other accounts, without any other user action, the researchers showed.

Concerningly, this could all happen by just opening the GIF — not by clicking or sharing it, as would normally be required to effect such an action.

It could also occur without the user’s awareness and effectively ‘worm’ its way through the entire user base for that organisation.

The researchers say this vulnerability could be exploited to impersonate leadership figures in the company and send out false information to employees. In turn, this could lead to financial damage or direct data leakage.

Microsoft Teams has seen a fivefold increase in uptake since the start of COVID-19, as more businesses make the switch to remote work and rely on videoconferencing to stay connected. Given this, the vulnerability had the potential for widespread damage.

However, since identifying the glitch, CyberArk Labs has now worked out a resolution in partnership with the Microsoft Security Research Centre.

Image credit: ©stock.adobe.com/au/Jaiz Anuar

Related News

Accenture to spend $6bn growing its OT security business

Accenture has arranged to acquire a majority stake in OT security company Dragos and complete two...

ACSC critical alert for Fortinet Firewalls and VPN Gateways

The Australian Cyber Security Centre has raised an alert that it is aware a widespread malicious...

Check Point and Illumio team up to counter AI threats

Check Point and Illumio have announced an expanded partnership aimed at helping organisations...


  • All content Copyright © 2026 Westwick-Farrow Pty Ltd