3 ms·
Whats your interpretation. The even acknowledged that the bug is an critical RCE on the desktop app. Coincidentally the desktop app is not part of the bug boun
by lhoff 6y ago
Whats your interpretation.
The even acknowledged that the bug is an critical RCE on the desktop app. Coincidentally the desktop app is not part of the bug bounty programm.
To be fair the impact on the desktop app is higher since it also has access to the OS and the attacker is not stuck inside the browser sandbox. But from my understanding it still is possible to steal the SSO token. When i think about O365 setups with OneDrive for Business and Sharepoint that means the attacker would have access to all files stored there. That usually means all company related files that person has. Additionally the attacker would have access to all emails and messages of the user.
How is that not critical?
And according to the Bug Bounty side, Spoofing bugs "do not qualify for this severity category".
- jtbayly 6y ago"from my understanding it still is possible to steal the SSO token" Isn't that precisely what spoofing is?
- lhoff 6y agoI wasn't arguing the spoofing part but the important vs. critical part. The same bug for ankther platform is ranked as critical. The thing is that according to Microsoft critical spoofing is not possible.
- donmcronald 6y ago> Isn't that precisely what spoofing is? Not in my opinion. I’ve always thought of spoofing as a write only type thing where you can impersonate someone, but not have access to any of their existing data. Email spoofing is a good example of this. Token theft is WAY more severe because it gives you complete access to everything. It’s total control. You can exfiltrate data and that’s what I’d consider the biggest difference, at least in my opinion.