Microsoft patches Azure Automation flaw enabling cross-tenant identity takeover
Microsoft has remediated a configuration vulnerability in Azure Automation that allowed unauthorized access to cross-tenant identities and data. The flaw stemmed from a public-by-default setting combined with code execution vulnerabilities, posing a significant risk to multi-tenant cloud environments. It remains unclear if the vulnerability was exploited in the wild prior to the patch.
Score Breakdown
Part of 2 situations
Microsoft Cloud Security: Azure Automation Flaw & 365 Outage
Microsoft has remediated a critical cross-tenant identity takeover vulnerability in Azure Automation and attributed a recent global Microsoft 365 outage to an automated network maintenance bug. The Azure Automation flaw, stemming from a public-by-default setting, posed a significant risk to multi-tenant environments, while the 365 outage highlights systemic vulnerabilities in automated infrastructure management. Both incidents are confirmed by Microsoft, though it remains unclear if the Azure Automation vulnerability was exploited in the wild.