An important Microsoft OneDrive feature has a worrying security error that can postpone user data


  • Researchers found an error in Microsoft OneDrive File Picker
  • The error stems in the lack of fine-grained OAuth permits
  • Microsoft acknowledges the error but has not fixed it yet

A vulnerability has been found in Microsoft’s OneDrive File Picker, which could give threat actors access to people’s entire cloud archives, experts have warned.

Security researchers OASIS discovered the error and reported it to Microsoft and noted that the problem lies in excessive permissions that File Picker asks – including reading access to the entire drive. The tool asks for these permits as OAUTH-SCOPES TO ONDRIVE is not fine-grained.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top