Microsoft has reacted quickly to a security vulnerability concerning its enterprise social networking vendor Yammer.
Redmond acquired Yammer in July 2012 for $1.2 billion ($772m) and has spent the last year building out a solid road map. Aside from growing the user and features base, Microsoft has also helped tighten up Yammer’s security.
This comes after a security report from researchers at Vulnerability Laboratory this week, detailed a remote authorisation bypass vulnerability in Yammer. The vulnerability potentially could have been exploited by a remote attacker without having a privileged application user account or there being any user interaction. The flaw was related to an insecure implementation of the OAuth authorisation technology Yammer uses.
But Microsoft reacted quickly. Vulnerability Laboratory reported the flaw to the Microsoft Security Response Center 10 July and got a response back 11 July. According to Microsoft, an automatic update for the flaw was pushed out 30 July.
“We have not detected any attacks, and there is no action for customers, as they are automatically protected,” a Microsoft spokesperson told eWEEK.
Microsoft is gaining respect from some observers for its security work. In addition to the Microsoft Security Response Center, Microsoft also has a robust security program in place for products. Known as the Security Development Lifecycle (SDL), the program has been emulated by other tech vendors. The SDL process bakes security practices into every step of the development and productisation process, and it is now one that Yammer benefits from as well.
“When Microsoft acquires a company, we begin a process of on-boarding that company and its products to our Security Development Lifecycle,” Microsoft’s spokesperson said.
How well do you know Internet security? Try our quiz!
Originally published on eWeek.
Fourth quarter results beat Wall Street expectations, as overall sales rise 6 percent, but EU…
Hate speech non-profit that defeated Elon Musk's lawsuit, warns X's Community Notes is failing to…
Good luck. Russia demands Google pay a fine worth more than the world's total GDP,…
Google Cloud signs up Spotify, Paramount Global as early customers of its first ARM-based cloud…
Facebook parent Meta warns of 'significant acceleration' in expenditures on AI infrastructure as revenue, profits…
Microsoft says Azure cloud revenues up 33 percent for September quarter as capital expenditures surge…