HomeSecurityCritical Microsoft bug allows modification of Bing results

Critical Microsoft bug allows modification of Bing results

A critical security vulnerability in Microsoft was disclosed, which gives hackers the ability to modify Bing's results and gain access to Outlook email.

Critical Microsoft bug allows modification of Bing results

Microsoft fixed a serious vulnerability in the Bing search engine, which would have allowed malicious actors to modify search results and gain access to Office 365 information.

In January 2023, Wiz security experts discovered a dangerous misconfiguration in the Microsoft Azure Active Directory (AAD) identity and access management system on the company's cloud platform.

This vulnerability can not only manipulate search engine results, but could also give outsiders unauthorized access to private Office 365 data , such as Outlook emails and calendar events, Teams messages, OneDrive files , and more.

See also: Will Microsoft's greed be the end of AI chatbots?

Common phenomenon

Some applications in Azure can use multi-tenant licensing and, therefore, be accessible to any Azure user . This means that developers need to define a way to authenticate users and track who has access to what. According to The Verge, this is where many people get it wrong, as misconfigurations in this regard are “a common occurrence.” Wiz says that 25% of all multi-tenant applications it scanned did not have good authentication.

That's exactly what happened with Bing Trivia, and it allowed researchers to log in with their own Azure accounts. Once logged in, they were given access to a content management system (CMS) that allowed to change live search results from Bing. The researchers said they didn't do anything spectacular here — anyone who knew how to get to the Bing Trivia page could have done the same thing.

See also: Microsoft Defender: Mistakenly flags URLs as malicious

Bing

In addition to changing search engine results, researchers also discovered that they were given access to other people’s Office 365 data, such as Outlook emails, calendars, Teams messages, OneDrive , and more. The researchers tested it on a virtual email inbox and confirmed the vulnerability. But the scope of the vulnerability doesn’t end there — there are more than 1,000 apps and websites in the Microsoft cloud that had similar abusive misconfigurations, including Mag News, PoliCheck, Cosmos, and more.

See also: Microsoft OneNote will block 120 dangerous file extensions

“A potential attacker could have affected Bing search results and compromised the Microsoft 365 emails and data of millions of people,” Ami Luttwak, Wiz’s chief technology officer, told the Wall Street Journal. “It could have been a nation-state trying to influence public opinion or a hacker with financial incentives.”

Microsoft was notified on January 31 and by March 20 fully addressed the vulnerability. Researchers found no evidence of prior exploitation.

Information source: techradar.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS