Uncategorized

Microsoft Azure Services Vulnerability Let Attackers Gain Unauthorized Access

Orca recently conducted an investigation into several Microsoft Azure services and discovered four instances where various services were uncovered to be susceptible to a Server Side Request Forgery (SSRF) attack.

There are two certain weaknesses present in the Azure platform that is particularly concerning because they do not require any form of authentication to access or exploit. 

This means that an attacker does not need to have a valid account or login credentials for the Azure platform in order to take advantage of these vulnerabilities. 

This lack of authentication makes it much easier for an attacker to gain unauthorized access or perform malicious actions and increases the likelihood of a successful attack.

The use of the word “concerning” emphasizes the severity of this security concern and highlights the need for immediate action to address these vulnerabilities.

How SSRF Works

Vulnerable Azure Services

The security vulnerabilities discovered by Orca between October 8, 2022, and December 2, 2022, are in the following services:-

  • Azure API Management
  • Azure Functions
  • Azure Machine Learning
  • Azure Digital Twins

After discovering these vulnerabilities Orca promptly reported Microsoft Security Response Center (MSRC) about them. As a result, MSRC fixed the problems quickly and Microsoft confirmed that the vulnerabilities were no longer present. 

Now, Orca is making the information about the vulnerabilities public, as they have been resolved. Below we have mentioned the general summary and the sequence of events of the vulnerabilities that were discovered in four Azure services.

Mitigations

Thankfully, the researchers’ attempts to exploit the SSRF vulnerabilities found in Azure were foiled, as Microsoft had already established various SSRF countermeasures within their cloud ecosystem, preventing access to IMDS endpoints.

In order to neutralize potential threats, organizations are urged to follow the actions that we have mentioned below:- 

  • Verify all input.
  • Establish that servers are designed to only permit necessary inbound and outbound communication.
  • Prevent misconfigurations.
  • Strictly follow the principle of least privilege (PoLP).
  • Keep the cloud environment secure.

Network Security Checklist – Download Free E-Book

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago