Authorization

Tenable Research Discovered a Download Hijack Vulnerability in Slack

COLUMBIA, Md., May 17, 2019 (GLOBE NEWSWIRE) -- TenableA®, Inc., the Cyber Exposure company, today announced that its research team discovered a vulnerability in the Slack Desktop Application for Windows that could have allowed an attacker to alter where a victima??s files are stored when the documents are downloaded within Slack.Slack has become a critical tool for many organizations looking to keep their employees connected. The vulnerability, which was found in Slack Desktop Application for Windows version 3.3.7 and has since been patched in version 3.4.0, could have allowed an attacker to send a crafted hyperlink via a Slack message that, once clicked, changes the document download location path to an attacker-owned file share. By exploiting the flaw, an attacker can not only steal future documents downloaded within Slack, but they can also manipulate them, such as injecting malicious code that would compromise the victima??s machine once opened.a??The digital economy and global distributed workforce have brought new technologies to market with the ultimate goal of seamless connectivity,a?? said Renaud Deraison, co-founder and chief technology officer, Tenable. a??But ita??s critical that organizations realize this emerging technology is potentially vulnerable and part of their expanding attack surface. Tenable Research continues to work with vendors such as Slack to disclose our discoveries to ensure consumers and organizations are secure.a??Slack has released version 3.4.0 to address this vulnerability. Users are urged to confirm that their Slack for Windows is updated to this latest version.For more information on how this vulnerability was found, read the Tenable Research blog post on Medium.About Tenable
TenableA®, Inc. is the Cyber Exposure company. Over 27,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. As the creator of NessusA®, Tenable extended its expertise in vulnerabilities to deliver the worlda??s first platform to see and secure any digital asset on any computing platform. Tenable customers include more than 50 percent of the Fortune 500, more than 25 percent of the Global 2000 and large government agencies. Learn more at tenable.com.

Contact Information:
Cayla Baker
Tenable
tenablepr@tenable.com
443-545-2102, x 1544
See also:
Leave a comment
News
  • Latest
  • Read
  • Commented
Calendar Content
«    Май 2019    »
ПнВтСрЧтПтСбВс
 12345
6789101112
13141516171819
20212223242526
2728293031