
The Zero Day Initiative (ZDI) collects and verifies reported vulnerabilities. Now there is probably a critical vulnerability in Azure with the highest CVSS value of 10.0. The BSI also warns about the vulnerability - but there still doesn't seem to be a patch for it.
The details of the critical security vulnerability in Azure with the CVSS score 10.0 are described briefly: "This vulnerability allows remote attackers to bypass authentication to Microsoft Azure. Authentication is not required to exploit this vulnerability."
Azure at risk – no patch to be found
As further explanation, there is a note that the specific error lies in the permissions granted to a SAS token. An attacker could exploit this vulnerability to launch a supply chain attack and execute arbitrary code on customer endpoints. The ZDI handed over the information about the vulnerability to Microsoft a long time ago: in October 2023. In the message There is even a link to be found, which leads to the Microsoft Security Updates. However, there is no information or patch to be found there.
There is currently no CVE number that could clarify the whole thing. The published vulnerability disclosure timeline shows the following:
Subscribe to our newsletter now
Read the best news from B2B CYBER SECURITY once a month- October 03.10.2023rd, XNUMX – Security vulnerability reported to the provider
- 06.06.2024/XNUMX/XNUMX - Coordinated public publication of the recommendation
- June 07.06.2024, XNUMX – Recommendation updated
It remains to be seen how Microsoft reacts to this in the next few days.
Who is the Zero Day Initiative (ZDI)?
The Zero Day Initiative (ZDI) was created to encourage researchers to confidentially report zero-day vulnerabilities to affected vendors through financial rewards. At the time, the perception in the information security industry was that those who discovered vulnerabilities were malicious hackers intent on causing harm. Some still believe that. While skilled, malicious attackers do exist, they represent only a small minority of the total number of people who actually discover new software vulnerabilities.
More at ZeroDayInitiative.com