HomeSecurityCritical vulnerability identified in Microsoft Azure!

Critical vulnerability identified in Microsoft Azure!

Researchers have discovered a critical vulnerability in Microsoft Azure named “BlackDirect” that allows hackers to take over Azure user accounts and generate Token with the victim’s permissions.

The vulnerability affected Microsoft OAuth 2.0 applications, which allow a malicious attacker to access and control the account .

Critical vulnerability identified in Microsoft Azure!

“OAuth is a protocol for authorization that is commonly used as a way for end users to allow websites or applications to access their information from other websites, without providing their secrets or passwords to the website or application.”

In the next generation, OAuth2 allows third-party applications to grant limited access to an HTTP service, and the client access can be a web page or a mobile app.

OAuth application trust domains and sub-domains are not registered on behalf of Microsoft and can be registered by anyone. By default, OAuth has approved the application and is allowed to request an “access_token”.

The researchers found that the combination of these two factors makes it possible to take action with the user – including accessing Azure resources, AD resources, and more.

Exploiting the BlackDirect vulnerability

To exploit the vulnerability, the researchers had initially listed all the command services in their account using the “Get-AzureADServicePrincipal” command.

They later found the URL allowed by Microsoft's application, in which some of the URLs end with ".cloudapp.net", ".azurewebsites.net" and .{vm_region}.cloudapp.azure.com" through the Microsoft Azure portal.

There are 3 following applications that are vulnerable to such an attack.

  • Portfolios
  • O365 Secure Score
  • Microsoft Service Trust

"This vulnerability makes it much easier to compromise privileged users – either through simple social engineering or through infection of a website that privileged users occasionally access."

As a result, the attacker will compromise the organization's entire domain and Azure environment.

Mitigation steps

  1. Make sure that all trusted redirect URLs configured in the application are owned by you.
  2. Remove unnecessary redirect URLs.
  3. Make sure the permissions requested by the OAuth application are the fewest it needs.
  4. Disable unused apps.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS