Teams meeting audio and roster data remain accessible via ACS Call Automation connectCall after a participant is removed from the meeting
Teams meeting audio and roster stay reachable via ACS Call Automation after a participant is removed.
Researcher Jacob Greenway disclosed that Microsoft Teams meeting audio and roster data remain accessible through Azure Communication Services Call Automation connectCall after a participant is removed. He reported the issue to the Microsoft Security Response Center before publishing a write-up and proof of concept. Testing was limited to meetings and tenants he owns. No CVE is named in the posted notice.
- Meeting audio and roster stay available after removal via ACS connectCall.
- Reported to MSRC before the Full Disclosure publication.
- Testing was limited to meetings and tenants the researcher owns.
- The disclosure includes a write-up and proof of concept.
Posted by Jacob Greenway on Sep 22 Hi Full Disclosure team, I'm not a traditional security researcher by background - I found this while working with the ACS and Teams SDKs and followed it through to a full writeup and PoC. I've done my best to be accurate and responsible throughout (reporting to MSRC first, giving advance notice of this disclosure date, and only testing against meetings/tenants I own), but if anything here is imprecise or doesn't match community...
This source does not provide full text. Read it at seclists.org.