Security researchers discovered a serious vulnerability in Microsoft’s Azure Automation Service that exposed other cloud tenants to attacks that might take complete control of their data and resources.
Security vendor Orca Security, which named the vulnerability AutoWarp, said the flaw put large companies in the telecommunications, car manufacturing, banking and acccounting sectors at risk.
The flaw was found in the Azure Automation Service, which allows cloud users to perform scheduled processes with input and output given inside a sandbox, isolating them from other customers’ programmes running on the same virtual machine.
Researchers were able to collect managed identity access tokens when Orca Security uncovered a mechanism to interface with the internal Azure server that administers sandboxes for other customers.
It would have been able to attack and compromise other Azure customers with the tokens in hand.


