Unauthorized account access made possible via an Azure ‘AutoWarp’ flaw

Security researchers discovered a serious vulnerability in Microsoft’s Azure Automation Service that exposed other cloud tenants to attacks that might take complete control of their data and resources.

Security vendor Orca Security, which named the vulnerability AutoWarp, said the flaw put large companies in the telecommunications, car manufacturing, banking and acccounting sectors at risk.

The flaw was found in the Azure Automation Service, which allows cloud users to perform scheduled processes with input and output given inside a sandbox, isolating them from other customers’ programmes running on the same virtual machine.

Researchers were able to collect managed identity access tokens when Orca Security uncovered a mechanism to interface with the internal Azure server that administers sandboxes for other customers.

It would have been able to attack and compromise other Azure customers with the tokens in hand.

Akshara Krishnan
Akshara Krishnan
Akshara Krishnan is passionate content and copywriter, who is highly interested and competent in the fields of digital marketing and supply chain management. She is an avid reader who enjoys books on self-help and psychology, and actively partakes in classical singing.

Similar Articles

Comments

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular