As discovered by two Vulnnerability researchers, Microsoft is not particularly careful with the security of the products and services it provides online to users .
According to The Register, researchers Numan Ozdemir and Ozan Agdepe discovered over 670 subdomains belonging to Microsoft that are exposed to risks.
The problem is that many of these subdomains could be exploited by malicious actors, who would use them to impersonate Microsoft in order to trick users. For example, one of the subdomains is identified as mybrowser.microsoft.com, which previously hosted details about the Edge.
The data for this subdomain is stored on an Azure server. So when a user tries to visit mybrowser.microsoft.com, the browser redirects them to a URL like 'webserver9000.azurewebsites.net'.
It is known that Microsoft is not careful enough when it comes to cleaning up DNS records for abandoned subdomains.
It may not be an extremely big threat, but a hacker could exploit these subdomains and trick a user.
A user could visit mybrowser.microsoft.com without knowing whether the site is malicious or is being used officially by the company. The attacker could exploit this ignorance to create a fake website and ask users to enter their credentials and other information.
The researchers immediately notified Microsoft of the vulnerability, and the company took down the subdomains they pointed out. The researchers also made a list of all the subdomains they were able to exploit to show that their finding was correct.
This is not the first case of subdomain exploitation. However, as the researchers report, Microsoft does not reward the discovery of vulnerabilities in its subdomains, which discourages many researchers from working on them.

