A Microsoft OneDrive Key Function has a disturbing security defect that could expose user data


  • The researchers found a flaw in Microsoft OneDrive Picker File
  • The flaw draws in the absence of a grain oauth license
  • Microsoft recognizes the defect, but has not yet corrected it

Vulnerability in the Microsoft OneDrive file selector has been found which could allow threat actors to access people’s cloud archives, experts warned.

Oasis security researchers discovered the defect and reported it to Microsoft, noting that the problem is in excessive authorizations that the file selector asks – including reading access to the whole player. The tool requires these authorizations because the Oauth glasses for OneDrive are not in fine grain.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top