Skip to main content

This mega Microsoft security flaw could let hackers change Bing results, access Outlook emails

Web Hosting & Remote IT Support

Microsoft has patched a high-severity vulnerability in its Bing search engine, which allowed potential threat actors to not only alter search results, but also access people’s Office 365 data.

Cybersecurity researchers from Wiz discovered the flaw in January 2023, identifying it as a misconfiguration in the Azure Active Directory (AAD) identity and access management service in Microsoft's Azure cloud platform.

Asides from changing search engine results, the flaw could allow access to other people’s Office 365 data, such as Outlook emails, calendars, Teams messages, OneDrive files, and more.

A common occurrence

Some applications on Azure can use multi-tenant permission, and thus be accessible by any Azure user. That means developers need to set up a way to validate users and keep tabs on who gets to access what. According to The Verge, this is where many get it wrong, as misconfigurations in this respect are “a common occurrence.” Wiz says 25% of all multi-tenant apps it scanned did not have good validation.

This is exactly what happened to Bing Trivia, and that allowed the researchers to log in with their own Azure accounts. Once logged in, they were granted access to a content management system (CMS) which let them alter live search results from Bing. The researchers said that they didn’t do anything spectacular here - anyone who knew how to reach the Bing Trivia page could have done the same.

Besides altering search engine results, the researchers also discovered they were given access to other people’s Office 365 data, such as Outlook emails, calendars, Teams messages, OneDrive files, and more. The researchers tested it out on a mock email inbox and confirmed the vulnerability. But the vulnerability’s reach doesn’t end here - there are more than 1,000 apps and websites on Microsoft cloud that had similar abusable misconfigurations, such as Mag News, PoliCheck, Cosmos, and more.

“A potential attacker could have influenced Bing search results and compromised Microsoft 365 emails and data of millions of people,” Ami Luttwak, Wiz’s chief technology officer, told The Wall Street Journal. “It could have been a nation-state trying to influence public opinion or a financially motivated hacker.”

Microsoft was tipped off on January 31, and by March 20, addressed the vulnerability entirely. The researchers did not find any evidence of prior abuse.

Via: The Verge



via Hosting & Support

Comments

Popular posts from this blog

These mobile games are just trying to steal your crypto hoard, FBI warns

Web Hosting & Remote IT Support The FBI has warned consumers about a newly-detected, fake "play-to-earn" mobile and online game that tricks victims into depositing cryptocurrency, only to later steal it.  In a public service announcement , the FBI said the elaborate scheme sees scammers first contact the potential victim and try to build a relationship with them.  After a little back-and-forth, the scammers would invite the victim to play an online or mobile game, in which players purportedly earn cryptocurrency rewards in exchange for some activity, “such as growing ‘crops’ on an animated farm” the FBI said.  Depositing cryptos But getting into the “game” isn’t free - the victims must first create a cryptocurrency wallet and deposit some money, which is where the real scam begins. The fraudsters would later also tell the victims that the more funds they deposit, the higher the gains will be. However, as soon as the victim stops depositing additional funds, the...

Want a remote control for your smart home? SwitchBot has made a Matter-compatible one

Web Hosting & Remote IT Support SwitchBot has launched a unique piece of tech capable of controlling smart home devices and infrared appliances. And the best part is you don’t need to connect it to a smartphone or to the internet as it functions perfectly offline.  Aptly named the SwitchBot Universal Remote , it has large spacious buttons, a navigation wheel in the middle, and a 2.4-inch LCD at the top. The company states in their announcement it sought to create a “user-friendly design” that everybody can understand. Now, you can’t just point the Universal Remote at a device and then push a button to issue commands immediately. According to Android Central , you must first choose what you want to control, which can be done by pressing the center red button. Pressing the main button will let you change which group of smart home devices to control.  Universal Remote has launched! 🚀 Consolidate all your remotes, and control everything at home, even #automation! NOW,...