Vectra: Microsoft Teams stores authentication tokens in unencrypted plaintext; Microsoft has no plans for a fix, since an exploit would require network access
and a fix is NOT in the pipeline Steve Zurier / SC Media : Vulnerability allows access to credentials in Microsoft Teams Monica J. White / Digital Trends : This Microsoft Teams exploit could leave your account vulnerable Tweets: @marcocantu : Interesting summary of a Teams vulnerability: “Electron does not support encryption or protected file locations by default [..], it is not considered secure enough for developing mission-critical products...” https://www.bleepingcomputer.com/ ... Chris Wiegman / @chriswiegman : This week is just getting more and more entertaining https://www.engadget.com/...
Context & Ripple Effects
Vectra's disclosure lands two years after Microsoft patched a Teams flaw that let malicious GIFs hijack accounts — a case where the company moved quickly once researchers showed account takeover was practical. This time the finding is different: authentication tokens sit in unencrypted plaintext files, and Microsoft is declining to fix it at all, reasoning that an attacker needs network access first.
The refusal makes this a policy story as much as a technical one. Microsoft has since shown it will reverse course under sustained researcher pressure, as when it fixed an Azure data-exposure flaw after Tenable's CEO publicly criticized the company, so the 'no plans' stance here sets up exactly that kind of standoff.
First-order effects
- Teams customers' credentials are readable by any malware or intruder that reaches the machine over the network, forcing security teams to lean on endpoint detection and network segmentation rather than a vendor patch.
- Vectra gains a high-profile disclosure, while Microsoft's own threat-modeling argument — network access required, therefore not worth fixing — becomes the public position defenders must plan around.
Second-order effects
- Security researchers have a template for escalation: the Tenable-driven Azure reversal shows public criticism can flip a 'won't fix' call, so expect pressure campaigns rather than quiet private disclosure when vendors decline findings.
- Rival collaboration platforms can weaponize the comparison in enterprise sales, attacking Microsoft's secure-development practices at the procurement stage.
Third-order effects
- If 'requires network access' becomes an accepted bar for skipping fixes, the industry's baseline assumption shifts from patch-everything to risk-acceptance-by-default, pushing buyers toward compensating controls and contractual security guarantees.
- The Electron angle raised in the surrounding commentary — the framework doesn't encrypt or protect file locations by default — points toward structural scrutiny of cross-platform app frameworks as a systemic credential-storage weakness across many vendors, not just Microsoft.
The trend: Enterprise software vendors are increasingly triaging vulnerabilities by attack prerequisites rather than fixing all disclosed flaws, leaving researcher pressure campaigns as the mechanism that reverses 'won't fix' decisions.