Critical Azure Cosmos DB flaw threatened cross-tenant database takeover

Summary

A critical vulnerability in Microsoft Azure's Cosmos DB, dubbed CosmosEscape, allowed researchers to escape the Gremlin query sandbox and execute code on shared infrastructure. This flaw could have enabled attackers to access any customer's database, including those used by Microsoft services like Entra ID, Teams, and Copilot, by obtaining a platform-wide credential.

IFF Assessment

FOE

This vulnerability poses a significant risk to defenders as it could allow attackers to compromise a wide range of Azure Cosmos DB instances, potentially leading to widespread data breaches.

Severity

9.0 Critical (AI Estimated)

The vulnerability allows for remote code execution and has a high impact on confidentiality and integrity, with a broad attack scope across a major cloud service. The ability to gain a platform-wide master key is a critical security failure.

Defender Context

This critical vulnerability highlights the importance of robust security for cloud database services and the need for continuous monitoring and prompt patching of infrastructure. Defenders should be aware of the potential for advanced persistent threats to exploit such systemic flaws.

Read Full Story →