This post has been republished via RSS; it originally appeared at: MSRC Security Update Guide.
An improper access control vulnerability in [GroupMe](https://groupme.com/) allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.