Microsoft has reacted quickly to a security vulnerability concerning its enterprise social networking vendor Yammer.
Redmond acquired Yammer in July 2012 for $1.2 billion ($772m) and has spent the last year building out a solid road map. Aside from growing the user and features base, Microsoft has also helped tighten up Yammer’s security.
This comes after a security report from researchers at Vulnerability Laboratory this week, detailed a remote authorisation bypass vulnerability in Yammer. The vulnerability potentially could have been exploited by a remote attacker without having a privileged application user account or there being any user interaction. The flaw was related to an insecure implementation of the OAuth authorisation technology Yammer uses.
But Microsoft reacted quickly. Vulnerability Laboratory reported the flaw to the Microsoft Security Response Center 10 July and got a response back 11 July. According to Microsoft, an automatic update for the flaw was pushed out 30 July.
“We have not detected any attacks, and there is no action for customers, as they are automatically protected,” a Microsoft spokesperson told eWEEK.
Microsoft is gaining respect from some observers for its security work. In addition to the Microsoft Security Response Center, Microsoft also has a robust security program in place for products. Known as the Security Development Lifecycle (SDL), the program has been emulated by other tech vendors. The SDL process bakes security practices into every step of the development and productisation process, and it is now one that Yammer benefits from as well.
“When Microsoft acquires a company, we begin a process of on-boarding that company and its products to our Security Development Lifecycle,” Microsoft’s spokesperson said.
How well do you know Internet security? Try our quiz!
Originally published on eWeek.
Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector
Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…
Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…
Judge Kaplan praises former FTX CTO Gary Wang for his co-operation against Sam Bankman-Fried during…
Explore the future of work with the Silicon In Focus Podcast. Discover how AI is…
Executive hits out at the DoJ's “staggering proposal” to force Google to sell off its…