HomeSecurityMicrosoft: Rejects report of critical Azure Backup vulnerability

Microsoft: Rejects Report of Critical Azure Backup Vulnerability

Microsoft has dismissed a security researcher's report of a critical vulnerability in Azure Backup for AKS , refusing to issue a CVE despite strong indications that the issue was silently patched. Researcher Justin O'Leary claims to have discovered a serious privilege escalation vulnerability that allowed cluster-admin access from the restricted "Backup Contributor" role .

See also: Microsoft 365 Backup: Restore individual files and folders

Azure

O'Leary discovered vulnerability in March and reported it to Microsoft on March 17.The Microsoft Security Response Center (MSRC) dismissed the report on April 13, claiming that the issue only involved gaining cluster-admin on a cluster where “the attacker already had administrative permissions.” The researcher calls this description misleading, noting that “the vulnerability allows a user with zero Kubernetes permissions to gain cluster-admin.”

Microsoft also described the MITRE submission as “ AI-generated content ,” which O’Leary believes does not address the technical elements of the report. After the rejection, the researcher escalated the issue to the CERT Coordination Center , which independently validated the vulnerability on April 16 and assigned it the identifier VU#284781 .

Azure Backup for AKS uses Trusted Access to grant backup extensions cluster-admin privileges within Kubernetes clusters . According to O'Leary , the vulnerability allowed anyone with only the Backup Contributor role on a backup vault to enable this Trusted Access relationship without already having Kubernetes permissions . An attacker could enable backup on a targeted AKS cluster , causing Azure to automatically configure Trusted Access with cluster-admin privileges .

See also: Vulnerability in Microsoft Azure API Management bypasses administrator restrictions

Microsoft: Rejects Report of Critical Azure Backup Vulnerability

From there, an attacker could extract secrets via backup operations or restore malicious workloads to the cluster. O'Leary categorized the issue as a Confused Deputy vulnerability (CWE-441) , where Azure RBAC and Kubernetes RBAC trust boundaries interacted in a way that bypassed expected authorization checks.

On May 4 , Microsoft staff contacted MITRE recommending against the CVE assignment , again arguing that the issue required pre-existing administrative access. CERT/CC later closed the case under CNA hierarchy rules , effectively leaving Microsoft (which is the CNA ) with the final authority to issue CVEs for its own products.

Despite Microsoft 's assurances that " no product changes have been made ," O'Leary noted that the original attack path no longer works after his report was published. " The current behavior returns errors that were not present in March 2024 ," he states. According to the researcher, Azure Backup for AKS now requires Trusted Access to be configured manually before enabling backup, reversing the previous behavior where Azure configured it automatically. 

See also: Microsoft: Azure Firewall integration with Security Copilot

Microsoft: Rejects Report of Critical Azure Backup Vulnerability

Additionally, he noticed additional permission checks that were missing during his initial testing in March. The MSI vault now requires Reader on both the AKS cluster and the snapshot. These changes suggest that Microsoft may have silently patched the vulnerability despite its public statements.

Source: bleepingcomputer

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS