Microsoft almost gave away the keys to everyone’s Azure Cosmos DBs

Summary

Microsoft narrowly averted a major security incident thanks to Google subsidiary Wiz discovering a critical vulnerability in Azure Cosmos DB's Gremlin API. This flaw could have allowed attackers to obtain the Cosmos Master Key, granting them read and write access to any database and access to a list of all databases on the service.

IFF Assessment

FOE

The article describes a critical vulnerability that could have led to widespread compromise of sensitive data within Microsoft's Azure Cosmos DB service.

Severity

9.8 Critical (AI Estimated)

This critical vulnerability, impacting authentication and access control, could allow remote attackers to gain complete control over all Azure Cosmos DB databases, leading to a complete loss of confidentiality, integrity, and availability.

Defender Context

This incident highlights the critical importance of securing cloud database services and the potential impact of vulnerabilities in foundational cloud infrastructure. Defenders should remain vigilant about security updates for cloud services and conduct regular audits of their cloud environments to identify and mitigate potential risks.

Read Full Story →