Search

Microsoft Warns Azure Customers of Flaw That Could Have Permitted Hackers Access to Data

Microsoft said it had fixed the flaw reported by Palo Alto Networks and it had no evidence malicious hackers had abused the technique.

Advertisement
Highlights
  • The report is second major flaw revealed in Microsoft's core Azure system
  • The Azure containers used code that had not been updated
  • Palo Alto reported the issue to Microsoft in July
Microsoft Warns Azure Customers of Flaw That Could Have Permitted Hackers Access to Data

Microsoft's acknowledgment focused on those customers who might have been somehow affected

Microsoft warned some of its Azure cloud computing customers that a flaw discovered by security researchers could have allowed hackers access to their data.

In a blog post from its security response team, Microsoft said it had fixed the flaw reported by Palo Alto Networks and it had no evidence malicious hackers had abused the technique.

It said it had notified some customers they should change their login credentials as a precaution.

The blog post followed questions from Reuters about the technique described by Palo Alto. Microsoft did not answer any of the questions, including whether it was confident no data had been accessed.

In an earlier interview, Palo Alto researcher Ariel Zelivansky told Reuters his team had been able to break out of Azure's widely used system for so-called containers that store programmes for users.

The Azure containers used code that had not been updated to patch a known vulnerability, he said.

As a result the Palo Alto team was able to eventually get full control of a cluster that included containers from other users.

"This is the first attack on a cloud provider to use container escape to control other accounts," said longtime container security expert Ian Coldwater, who reviewed Palo Alto's work at Reuters' request.

Palo Alto reported the issue to Microsoft in July. Zelivansky said the effort had taken his team several months and he agreed that malicious hackers probably had not used a similar method in real attacks.

Still, the report is the second major flaw revealed in Microsoft's core Azure system in as many weeks. In late August, security experts at Wiz described a database flaw that also would have allowed one customer to alter another's data.

In both cases, Microsoft's acknowledgment focused on those customers who might have been somehow affected by the researchers themselves, rather than everyone put at risk by its own code.

"Out of an abundance of caution, notifications were sent to customers potentially affected by the researcher activities," Microsoft wrote on Wednesday.

Coldwater said the problem reflected a failure to apply patches in a timely fashion, something Microsoft has often blamed its customers for.

"Keeping code updated is really important," Coldwater said. "A lot of the things that made this attack possible would no longer be possible with modern software."

Coldwater said that some security software used by cloud customers would have detected malicious attacks like the one envisioned by the security company, and that logs would also show signs of any such activity.

The research underscored the shared responsibility between cloud providers and customers for security.

Zelivansky said cloud architectures are generally safe, while Microsoft and other cloud providers can make fixes themselves, rather than rely on customers to apply updates.

But he noted that cloud attacks by well-funded adversaries, including national governments, are "a valid concern."

© Thomson Reuters 2021


How will India's new liberalised drone rules impact the industry? And where are they left wanting? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Microsoft, Azure
 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 13T Chipset, Rear Camera Details Revealed in New Teasers
  2. Lenovo Legion Y700 4th Gen Tablet Confirmed to Launch in May
  3. CMF Phone 2 Pro Confirmed to Feature a Total of Three Rear Cameras
  4. Infinix Note 50s 5G+ With 64-Megapixel Rear Camera Launched in India
  5. Oppo A5 Pro 5G Confirmed to Arrive on This Date in India
  6. Asus Refreshes TUF Gaming A14 With Nvidia GeForce RTX 5060 Laptop GPU
  7. Oppo A5 Pro 5G Price in India Leaked Ahead of April 24 Launch
  8. OnePlus Pad 2 Pro Allegedly Spotted on Geekbench With This Chipset
  9. Nvidia GeForce RTX 5060, GeForce RTX 5060 Ti Price in India Announced
  10. Oppo K12s 5G Launch Date, Design, Colours and Key Features Confirmed
  1. Atomfall's Game Pass Launch a 'Huge Success', Rebellion CEO Says
  2. OnePlus Pad 2 Pro Allegedly Spotted on Geekbench With Snapdragon 8 Elite Chipset
  3. Oppo A5 Pro 5G Price in India Leaked Ahead of April 24 Launch
  4. OpenAI Unveils Codex CLI, an Open-Source Agentic Coding Assistant That Can Operate Locally
  5. Google to Appeal Against Part of US Court's Decision in Monopoly Case
  6. Lenovo Legion Y700 4th Gen Tablet Officially Teased; Confirmed to Launch in May
  7. NASA Hubble Space Telescope Helps Confirm the First Solitary Black Hole
  8. CMF Phone 2 Pro Rear Camera Unit Teased; Confirmed to Get a Telephoto Sensor
  9. Indian Telecom Operators May Hike Tariffs by December 2025 As Part of Tariff Repair Efforts: Report
  10. OpenAI Introduces Flex Processing in API to Help Developers Cut AI Usage Costs
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »