Tech

A key Microsoft OneDrive feature has a worrying security flaw which could expose user data

Share
Share


  • Researchers found a flaw in Microsoft OneDrive File Picker
  • The flaw stems in the lack of fine-grained OAuth permissions
  • Microsoft acknowledges the flaw, but hasn’t fixed it yet

A vulnerability in Microsoft’s OneDrive File Picker has been found which could allow threat actors to access people’s entire cloud archives, experts have warned.

Security researchers Oasis discovered the flaw and reported it to Microsoft, noting the problem lies in excessive permissions that File Picker asks for – including read access to the entire drive. The tool asks for these permissions since the OAuth scopes for OneDrive aren’t fine-grained.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Textile engineer develops 3D-printed material to boost mobility in protective clothing
Tech

Textile engineer develops 3D-printed material to boost mobility in protective clothing

Image shows the 3D-printed auxetic structure. Credit: Heriot-Watt University A textile engineer...

Gaming fans bring electric energy to Rotterdam as TwitchCon arrives
Tech

Gaming fans bring electric energy to Rotterdam as TwitchCon arrives

Rotterdam hosts TwitchCon — the annual event run by United States streaming...

Insane 150TB hard drives are real—well, almost! Seagate teases future with monster 15TB platters
Tech

Insane 150TB hard drives are real—well, almost! Seagate teases future with monster 15TB platters

Seagate’s HAMR roadmap could deliver 150TB hard drives – but not before...