Unauthorized Access to Cross-Tenant Applications in a Microsoft Azure Service

Freki123

Level 16
Thread author
Verified
Top Poster
Aug 10, 2013
759
A researcher at Tenable has discovered an issue that enables limited, unauthorized access to cross-tenant applications and sensitive data (including but not limited to authentication secrets).
Tenable is continuing to work with Microsoft to coordinate the disclosure process, and will update this advisory with more details by 28 September 2023.

Since MS still needs time to fix it in the second try no proofs-of-concept published.

Edit for added source:

“To give you an idea of how bad this is, our team very quickly discovered authentication secrets to a bank,” Yoran wrote. “They were so concerned about the seriousness and the ethics of the issue that we immediately notified Microsoft.”
 
Last edited:

Freki123

Level 16
Thread author
Verified
Top Poster
Aug 10, 2013
759
Nothing screams more "We take security seriously" than the timeline. Bug reported and nothing happens for three month till the first "partial" fix :D
But the moment you report the problem to the media MS starts to move at rocketspeed...
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top