Vectra: Microsoft Teams stores authentication tokens in unencrypted plaintext mode; Microsoft has no plans for a fix, since an exploit requires network access
Microsoft downplayed the flaw saying it ‘does not meet our bar for immediate servicing.’ — Microsoft Teams stores authentication tokens …
Context & Ripple Effects
Vectra's disclosure puts a name on a long-running tension in Microsoft's security posture: Teams has been here before, when Microsoft patched a flaw that let attackers hijack accounts via malicious links and GIFs back in 2020. This time the finding is different in kind — authentication tokens sitting in unencrypted plaintext on disk — and different in response: Microsoft says it will not fix it.
The company's stated reasoning is that an exploit requires network access and therefore 'does not meet our bar for immediate servicing.' That bar has been contested before on Azure, where Microsoft only moved to fix a sensitive-data flaw after public criticism from Tenable's CEO. Vectra going public looks like an attempt to apply the same pressure.
First-order effects
- Teams users on networks where an attacker can gain access — shared offices, compromised endpoints — have credentials readable in plaintext with no patch coming, shifting mitigation onto customers' own network controls.
- Vectra's public disclosure forces Microsoft to defend its 'won't fix' decision in the open rather than resolve it privately with the researcher.
Second-order effects
- Other security firms now have a template: disclose publicly first, since Microsoft's own history shows the Azure fix came only after Tenable's CEO criticized the company publicly.
- Enterprise buyers evaluating Teams against rivals gain a concrete data point on how Microsoft triages flaws that fall below its servicing bar, feeding procurement and risk assessments.
Third-order effects
- If vendors increasingly route low-severity-but-sensitive findings into a permanent 'won't fix' tier, the effective arbiter of cloud security standards shifts from vendor severity scoring to whichever researcher can generate enough public pressure — an informal, adversarial patch-governance regime.
- The pattern pushes enterprises toward assuming token theft is survivable at the architecture level — short-lived credentials, device-bound sessions — rather than waiting on application vendors to encrypt storage.
The trend: Cloud vendors' decisions on which vulnerabilities deserve fixing are increasingly settled by public researcher pressure rather than internal severity bars, making disclosure itself a negotiation tactic.