Kanth Kolluru

My feedback

  1. 372 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    35 comments  ·  Public » IT Pro  ·  Flag idea as inappropriate…  ·  Admin →
    Kanth Kolluru commented  · 

    Hi, Is there any progress on this? Auto update seems to have been compromised with a vulnerability identified where it can be tweaked to download package from any source instead of just Microsoft teams update packages. Being able to control the auto update behavior has become all the more crucial now.

    https://www.bleepingcomputer.com/news/security/microsoft-teams-can-be-used-to-download-and-run-malicious-packages/

    https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12

Feedback and Knowledge Base