🚂Cisco Talos, a cybersecurity company, recently discovered eight vulnerabilities in the Microsoft 365 app for macOS. Hackers can use these vulnerabilities to bypass the macOS permission model and use existing application permissions to perform malicious operations without additional user verification. In short,Hackers can send emails, record audio, take photos or videos without the user's permission.#安全漏洞 #微软故障 #钱包被盗
Talos reported these vulnerabilities to the Microsoft team, and Microsoft responded that these vulnerabilities are of low risk. Since these Microsoft applications need to allow unsigned libraries to be loaded to support plug-in functionality, these vulnerabilities cannot be fixed. However, Microsoft has fixed the vulnerabilities for the following applications that do not support plug-ins:
Microsoft Teams (work or school) app
Microsoft Teams (work or school) web version
Microsoft Teams (work or school) desktop version
Microsoft OneNote
However, the following four applications still have vulnerabilities:
Microsoft Excel
Microsoft Outlook
Microsoft PowerPoint
Microsoft Word