Forum Discussion

jimlehmer's avatar
jimlehmer
Copper Contributor
Nov 13, 2019

Opening a browser from Teams app will open a browser started under "Run as" as a different user

We often start IE using "Run As" to access various admin apps under different accounts. If I am logged into Windows as my normal id "jim" and then start IE using Run As to run as "jimadmin," and that IE is the only IE session running at the time in Windows, then when clicking on a link in the Teams APP (not browser, the app), it opens the link in the IE session that is under "jimadmin," instead of starting a new IE process as "jim" as I would expect. This seems like a BIG security hole - con someone into click the wrong link while their session is elevated and pwn them.

No RepliesBe the first to reply

Resources