Microsoft patches Azure Automation flaw enabling cross-tenant identity takeover
Microsoft has remediated a configuration vulnerability in Azure Automation that allowed unauthorized access to cross-tenant identities and data. The flaw stemmed from a public-by-default setting combined with code execution vulnerabilities, posing a significant risk to multi-tenant cloud environments. It remains unclear if the vulnerability was exploited in the wild prior to the patch.
Score Breakdown
Part of 2 situations
Microsoft Azure Vulnerabilities and Outage Impact US Cloud Infrastructure
Microsoft has addressed a critical cross-tenant identity takeover vulnerability in Azure Automation and attributed a recent global Microsoft 365 outage to an automated network maintenance bug. These incidents confirm systemic risks within Microsoft's cloud infrastructure, impacting multi-tenant environments and service availability. It remains unclear if the identity takeover vulnerability was exploited prior to remediation.