Security News > 2020 > March > Azure Red Flag: Microsoft Accidentally Fixes Cloud Config ‘Bug’

Azure Red Flag: Microsoft Accidentally Fixes Cloud Config ‘Bug’
2020-03-18 21:14

UPDATE. Researchers are shedding light on a Microsoft Azure misconfiguration bug that leaked sensitive access tokens, which could have given hackers access to virtual machine instances and cloud-based storage buckets.

According to CyberArk, it found the bug in September and Microsoft "Unintentionally" fixed it within two weeks as part of a regular update to its Azure platform.

Researchers said the Microsoft Azure Portal bug is tied to URL parsing within a JavaScript file used within Azure's Extension Manifest.

The Microsoft Azure Portal is a web-based and unified console for building, managing and monitoring cloud infrastructure.

"In this vulnerability in Microsoft Azure, attackers could take over Azure Accounts by exploiting a misconfiguration bug in Azure Portal's manifest," wrote Omer Tsarfati, a cyber security researcher at CyberArk. "Microsoft ended up fixing this bug, unintentionally, before we could officially report it to them."


News URL

https://threatpost.com/azure-red-flag-microsoft-fixes-cloud-config-bug/153928/?utm_source=rss&utm_medium=rss&utm_campaign=azure-red-flag-microsoft-fixes-cloud-config-bug

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 663 794 4391 4085 3666 12936