Default Azure Automation Setting Enables Cross-Tenant Identity Takeover

Summary

Microsoft has fixed a critical vulnerability in Azure Automation that allowed attackers to take over identities in other tenants. This flaw could have led to unauthorized access to sensitive data, credentials, and cloud workloads. The issue stemmed from a default configuration setting and a chain of code flaws.

IFF Assessment

FOE

This vulnerability represents a significant security risk, as it allows attackers to gain unauthorized access to other tenants' resources, which is detrimental to defenders.

Severity

9.0 Critical (AI Estimated)

The CVSS score is estimated to be high due to the potential for widespread impact across tenants, the ease of exploitation through a default configuration, and the severe impact of identity takeover and data access.

Defender Context

This incident highlights the critical importance of reviewing default configurations in cloud services, as they can often harbor security risks. Defenders should proactively audit their Azure Automation settings and any other multi-tenant cloud services for similar misconfigurations. Prompt patching and vulnerability management remain essential to prevent such cross-tenant attacks.

Read Full Story →