$4.99/mo - Save 61% With Exclusive 2-Year Plan + 4 Months Free!Claim Now

Microsoft Flaw Exposed Power Platform to Credential Theft

  • Last updated February 4, 2025
  • written by
    Writer

Seattle, February 4, 2025 –A critical Microsoft SharePoint Connector flaw in the Power Platform put millions of credentials at risk. Hackers could have exploited it to steal user tokens, escalate access, and infiltrate corporate networks.

In a shocking revelation, cybersecurity researchers have uncovered a high-risk vulnerability in Microsoft’s Power Platform SharePoint Connector, potentially exposing sensitive corporate credentials.

The flaw, classified as a Server-Side Request Forgery (SSRF) exploit, could have allowed hackers to impersonate users, steal SharePoint access tokens, and compromise entire organizations.

Dmitry Lozovoy, Senior Security Researcher at Zenity Labs said:

The vulnerability, which persisted until December 13, 2024, was first reported to Microsoft in September 2024. During this window, organizations relying on Microsoft’s low-code development tools were exposed to severe security risks.

Cybercriminals could have leveraged the flaw to access SharePoint APIs, extract confidential data, and even embed malicious applications into Microsoft Teams. A cybersecurity expert at Binary Security warned:


Other News At VPNRanks


Hey, wait!

Stay informed on the latest privacy updates, cybersecurity insights, and internet freedom news by following VPNRanks news daily! As your primary resource for critical updates in online security, we ensure you’re always in the know. Make VPNRanks your go-to guide for safeguarding your digital life.

Leave a Reply

Your email address will not be published. Required fields are marked *