The Register Home Page

back to article One token to pwn them all: Entra ID bug could have granted access to every tenant

A security researcher claims to have found a flaw that could have handed him the keys to almost every Entra ID tenant worldwide. Dirk-jan Mollema reported the finding to the Microsoft Security Research Center (MSRC) in July. The issue was fixed and confirmed as mitigated, and a CVE was raised on September 4. It is, however, …

  1. FILE_ID.DIZ
    WTF?

    Microsoft apparently gave the middle finger back to the US Government and CISA after the latter's dressing down of Microsoft from the 2023 Exchange Online breach.

    But at least we have CoPilot... instead of a more secure Azure... I guess.

    https://www.theregister.com/2024/04/03/cisa_microsoft_exchange_online_china_report/

  2. Mister Dubious
    Thumb Down

    Security by wilful obscurity

    "...Microsoft had not detected any abuse of the vulnerability..."

    "I see nothing! I hear nothing! I know nothing!" -- Oberfeldwebel (Sergeant) Hans Schultz

    1. elsergiovolador Silver badge

      Re: Security by wilful obscurity

      Seems like this is a carefully crafted phrase, presumably by the legal team.

      If you were exploiting the flaw, surely you would slurp data at a rate that will be buried in telemetry background noise.

  3. elsergiovolador Silver badge

    Security

    Security is micro and soft.

    I mean, it's in plain sight.

    So reassuring that government uses Microsoft software.

  4. Doctor Syntax Silver badge

    undocumented impersonation tokens called "Actor tokens"

    Remind me again how one of Linux's weaknesses is that it doesn't have something something Active Directory something something logins something something company wide something 1000s of users something.

    1. dmesg Bronze badge

      ... yeah, you just have to settle for LDAP and Kerberos. And configure them to the way you run your network/business rather than the other way around.

  5. ginolee

    I'm curious as to the details of this vulnerability. Was it a mistake due to incompetence or was it a mistake that many reasonably intelligent programmers might have also made? Also, how did it pass code review?

    1. Whitter
      Joke

      Icon required

      If you are going to reference Microsoft code review (or the equivalently missing test), one should use the Joke icon :)

    2. storner
      Black Helicopters

      If I were the NSA, I would say it was very competently done.

      Too bad some schmuck discovered it.

      1. zeigerpuppy

        I agee, this sounds more like a deliberate backdoor than an accident al vuln... (But i have not reviewed the CVE)

        1. Blazde Silver badge

          It's far too easy to exploit to be deliberate. Can't be anything other than pure incompetence at the process level eg. lack of adequate code review for such a critical system.

  6. Jou (Mxyzptlk) Silver badge

    This fits to the known general quality issues.

    Shortcuts everywhere to make it work as cheap as possible. Which known results.

  7. BartyFartsLast Silver badge

    "Microsoft had not detected any abuse of the vulnerability"

    Yup, they checked for log files and found none.

    1. exovert

      what are they using for checking these log files, is it purview? if it was only reported in july, the log queries would still be queued

  8. Anonymous Coward
    Anonymous Coward

    What do you expect

    What one can expect when all the old security paradigms have been shifted up side down with all the trendy adoptions like cloud and microservices. The old architecture based on rings of security with ring zero requiring physical access has long gone and now is all based on digital identity and that can always be exploited remotely. The attacker just need some human flaw. Now with advent of vibe coding expect tones of these issues in the future. My home network is probably more secure than this flaw was showing. Not sure how MS can go on this without being bruised. This is 10+ CVE finding by the wide acres of the attack surface.

    1. Anonymous Coward
      Anonymous Coward

      Re: What do you expect

      Agreed, but the same identity-based security is used by all SaaS (and a lot of PaaS) providers. This isn't just a Microsoft thing.

      It's great when it works, but your stuff is literally wide open to the internet when it doesn't. It's why "we" segregate our own networks with firewalls, because we found out the hard way that not having a login to a system didn't necessarily mean you couldn't access or damage it.

      At least we know security researchers are prodding away at this stuff... and we can be reasonably sure that the providers will take these reports seriously. There's some small comfort to be had there.

      Genuine question: If you access files in 365 via the Graph API there's no file access logging done? Is that really the case?

  9. Anonymous Coward
    Anonymous Coward

    Private Cloud IS the Answer

    Folks, not sure if this is enough for you to rethink the folly of a public cloud first approach if you value the privacy of your or your company's data, but hopefully it is.

    Stop being lazy and letting someone you don't know risk your own resume generating event, or worse.

    Please.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like