Site icon Auspreneur

According to the researcher, an Azure bug enabled password theft

Amazon

A security report from Tenable researchers prompted Microsoft to address and resolve a cross-tenant information disclosure vulnerability within its Azure cloud services.

Azure Vulnerability Allowed Unauthorized Access and Password Theft Tenable identified a flaw that resulted in “limited, unauthorized access to cross-tenant applications and sensitive data, including authentication secrets.” The issue stemmed from insufficient access controls in Azure Function hosts, which are initiated when customers utilize custom connections in Microsoft’s Power Platform.

Exploiting this vulnerability, an attacker could pinpoint the hostname of an Azure Function linked to a custom connector, enabling interaction with the function without requiring authentication. By exploiting slight differences in hostnames, an enumeration attack could be executed, gradually revealing other users.

Consequently, this loophole allowed interception of OAuth client IDs, secrets, and other authentication forms associated with unsecured Azure Function hosts.

Microsoft’s Response and Patching Timeline Microsoft acknowledged that only Tenable’s researcher had achieved “anomalous access” using the vulnerability and subsequently addressed the issue. However, the deployment of the patch encountered delays.

Tenable reported the vulnerability on March 30, and Microsoft managed to patch it for the “majority” of customers by June 7. However, subsequent testing by Tenable revealed an incomplete fix, as a “very small subset of custom code in a soft deleted state were still impacted.” This state, meant for swift recovery in case of custom connector deletion, posed a lingering risk.

Microsoft completed the patching process by August 2, rectifying the issue comprehensively.

Tenable’s CEO Expresses Frustration Tenable’s Chairman and CEO, Amit Yoran, vented his frustration in an impassioned LinkedIn post, criticizing Microsoft for its lack of transparency and sluggish response to the vulnerability.

Yoran highlighted Microsoft’s over 90-day delay in implementing a partial fix, which exclusively covered new applications loaded into the service. Yoran expressed anticipation that the complete fix, slated for August, might not be fully effective until September.

He emphasized the importance of the shared responsibility model endorsed by cloud providers and noted its breakdown when the cloud vendor fails to promptly notify users of emerging issues and openly apply necessary fixes.

Exit mobile version