https://www.zerodayinitiative.com/advisories/ZDI-24-581/ thezdi Menu * PRIVACY * WHO WE ARE * HOW IT WORKS * BLOG * ADVISORIES * LOG IN SIGN UP * Menu * PRIVACY * WHO WE ARE * HOW IT WORKS * BLOG * ADVISORIES * LOG IN * SIGN UP * thezdi * Trend Micro Advisory Details June 6th, 2024 Microsoft Azure SQL Managed Instance Documentation SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability ZDI-24-581 ZDI-CAN-22281 CVE ID CVSS SCORE 10.0, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H AFFECTED Microsoft VENDORS AFFECTED Azure PRODUCTS This vulnerability allows remote attackers to bypass authentication on Microsoft Azure. Authentication is not required to exploit this vulnerability. VULNERABILITY DETAILS The specific flaw exists within the permissions granted to an SAS token. An attacker can leverage this vulnerability to launch a supply-chain attack and execute arbitrary code on customers' endpoints. Microsoft has issued an update to correct this ADDITIONAL vulnerability. More details can be found at: DETAILS https://msrc.microsoft.com/update-guide/en-us/ acknowledgement/online * 2023-10-03 - Vulnerability reported to vendor DISCLOSURE * 2024-06-06 - Coordinated public release of advisory TIMELINE * 2024-06-07 - Advisory Updated CREDIT Nitesh Surana (@_niteshsurana) of Trend Micro Research BACK TO ADVISORIES General Inquiries zdi@trendmicro.com Find us on X @thezdi Find us on Mastodon Mastodon Media Inquiries media_relations@trendmicro.com Sensitive Email Communications PGP Key WHO WE ARE * Our Mission * Trend Micro * TippingPoint IPS HOW IT WORKS * Process * Researcher Rewards * FAQS * Privacy ADVISORIES * Published Advisories * Upcoming Advisories * RSS Feeds BLOG thezdi