Security researcher Peter Adkins managed to gain access to one of Microsoft's servers after exploiting a security flaw he discovered in Adobe AEM in late 2015.
Adkins' story is proof once again that, in most cases, and especially in the real world, attackers tend to combine flaws in multiple projects to gain access to a company's servers.
During his work as a professional bug bounty hunter, the researcher discovered a vulnerability in Adobe Experience Manager (formerly known as CQ5 or Communique5), a Java-based CMS that the company purchased in 2010.
The flaw, CVE-2016-0957, exists in the Dispatcher component included in the Apache AEM CMS that allows an attacker to bypass URL filters, in order to restrict someone's access to a specific part of the CMS.
By chance, and not actively looking for bugs, at some point after discovering the AEM issue, the researcher had just logged out of their Microsoft account and was redirected to a page at signout.live.com.
Since he was already used to Adobe AEM pages, he quickly noticed that Microsoft was using this CMS for this part of their services. Naturally, he tried bypassing the URL filters on Microsoft servers.
His exploit worked and he was immediately prompted to log in via a popup, a sign that he had managed to bypass the URL filters and was allowed to access a restricted section of the CMS.
However, this is where things stop being security vulnerabilities and move into mistrust. Adkins was able to log in to one of Microsoft's Adobe AEM installations with his default credentials: admin / admin.
On the backend, he had access to the entire CMS, and was able to load his own AEM modules that would run on Microsoft websites.
The researcher worked with both Adobe and Microsoft to fix these issues. Adobe issued an update for AEM in February, while Microsoft patched AEM later in May. Unfortunately for Adkins, the signout.live.com domains are not included in Microsoft's bug bounty program and Adobe does not run a bug bounty program, so his work went unrewarded.


