Critical Flaw Led to Azure Cosmos DB Pwnage

https://www.securityweek.com/wp-content/uploads/2024/08/Microsoft-Azure.jpeg

A critical vulnerability in the Azure Cosmos DB database service could have allowed attackers to compromise all databases on the service, cybersecurity outfit Wiz reports.

Referred to as CosmosEscape, the security defect could have allowed an attacker to obtain a platform-wide key and retrieve the primary key of any Cosmos DB account, gaining full read and write access across the service.

Armed with the key, an attacker could have listed all databases on the service, filtering them by specific organization identifiers, such as subscription and tenant IDs.

“Chained together, these capabilities could have enabled precision targeting at platform scale: from identifying a specific organization’s databases to compromising them, all from publicly accessible endpoints,” Wiz says.

According to the cybersecurity firm, because Microsoft uses Cosmos DB to store data across Entra ID, Teams, and Copilot, the vulnerability potentially exposed the tech giant’s databases to unauthorized access.

The issue could have...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more