Check Point cybersecurity researchers have revealed details of two potentially dangerous flaws in Microsoft Azure services that could allow hackers to target and exploit many businesses that run their web and mobile applications on Azure. Azure App allows users to build web and mobile applications for any platform or device and easily integrate them with SaaS solutions , in-house applications to automate business processes .
According to a report shared by researchers on The Hacker News, the first security (CVE-2019-1234) is a spoofing issue that affected Azure Stack (a software from Microsoft).
This flaw would allow a hacker to remotely gain unauthorized access to screenshots and sensitive information of any virtual machine running Azure. According to the researchers, this flaw can be exploited by hackers through the Microsoft Azure Stack Portal, an interface where users can access the clouds they have created using Azure Stack.
By leveraging a secured API, the researchers found a way to gain access to the virtual machine name and identity , hardware information (cores, total memory) of the targeted machines , and then use it with another unauthenticated HTTP request to steal screenshots.
As for the second bug (CVE-2019-1372), this is related to remote code execution that affected the Azure App service on Azure Stack, which would give a hacker the ability to gain full control of the entire Azure server and consequently take control of a company 's business code .
A hacker can exploit both of these flaws by creating a free account and performing malicious operations on it or sending unauthenticated HTTP requests to an Azure Stack user portal.
Check Point researcher Ronen Shustin, who discovered the bugs, reported them to Microsoft, preventing hackers from causing serious damage and chaos. After fixing both bugs, the company rewarded Shustin with $40,000 under the Azure bug bounty program
