Skip to content
Techzine Europe
  • Home
  • Topstories
  • Topics
    • Analytics
    • Applications
    • Collaboration
    • Data Management
    • Devices
    • Devops
    • Infrastructure
    • Privacy & Compliance
    • Security
  • Insights
    • All Insights
    • Agentic AI
    • Analytics
    • Cloud ERP
    • Generative AI
    • IT in Retail
    • NIS2
    • RSAC 2025 Conference
    • Security Platforms
    • SentinelOne
  • More
    • Become a partner
    • About us
    • Contact us
    • Terms and conditions
    • Privacy Policy
  • Techzine Europe
  • Techzine Netherlands
Techzine News Security Serious Azure Active Directory vulnerability resolved by Microsoft
2 min Security

Serious Azure Active Directory vulnerability resolved by Microsoft

Erik van KlinkenJune 21, 2023 12:07 pmJune 21, 2023
Serious Azure Active Directory vulnerability resolved by Microsoft

Microsoft has fixed an exploit in Azure Active Directory (AD) authentication. The vulnerability allowed intruders to escalate account privileges and control the entire account.

Organizations deploy Azure AD to control user access. Examples include providing the backend for Office 365 users or centralising authentication between on-prem and cloud-based environments.

nOAuth

The misconfiguration has been called nOAuth by Descope, the party that discovered the vulnerability. AD OAuth applications that use email claims to generate access tokens are at risk. The process for exploitation sounds as simple as it is worrisome. A threat actor’s Azure AD admin account need only have a target’s email address for reference to log into a vulnerable application. From then on, privileges can be escalated, including lateral movement within the affected environment.

In a blog, Descope identifies where things went wrong with Azure AD’s configuration. The email claim is mutable and does not require authentication to count as an identifier. Microsoft already discouraged users from using email for login, according to Descope.

Vulnerable

Descope does not name the targets by name, but speaks of “several major applications” that were exploited. This included a design app with millions of monthly users, a publicly traded customer experience company and a multi-cloud consulting firm. Administrators of vulnerable applications can turn to Descope’s “Suggested remediation steps” for help.

Given Azure AD’s massive market share within the identity and access management world (27.53 percent according to 6sense), such a vulnerability could potentially do a considerable amount of damage. However, Microsoft has already contacted vulnerable parties behind the scenes after it received word from Descope about the exploit on April 11.

Also read: Microsoft Bing penetrated through misconfiguration in Azure Active Directory

Tags:

account privileges / Azure Active Directory / vulnerability

"*" indicates required fields

Stay tuned, subscribe!

Nieuwsbrieven*
This field is for validation purposes and should be left unchanged.

Related

Cisco closes serious security vulnerability in Wireless LAN Controllers

SAP confirms NetWeaver vulnerability is being actively exploited

Commvault vulnerability poses serious risk to company data

Emergency Windows update solves Active Directory problem

Editor picks

Quantum Network Entanglement Chip is Cisco’s foundation for quantum networks

New development could make quantum faster a reality

ServiceNow aims to disrupt Salesforce with new AI-based CRM

The battle of the titans

SAS gives data scientists the steering wheel for the AI (agents) era

Its rich history makes SAS a trusted platform for data scientists. Ho...

The Techzine Perspective: RSAC 2025 is about AI security, integrated solutions, and the quantum threat

AI has a huge impact on cybersecurity

Insight: IT in Retail

E-commerce solutions provider puts its own portfolio on display

Commercetools launches semi-annual showcase 'Compilations'

Intel and Altera aim to bring AI to edge computing with new series of chips

Intel and subsidiary Altera have unveiled new chips and FPGAs optimiz...

AI-powered cameras shake up retail

AI-powered cameras shake up retail

Stores are deploying AI-powered cameras in multifaceted ways. Everyth...

Manhattan Associates provides supply chain software, is it more than a fancy name?

Manhattan Associates provides supply chain software, is it more than a fancy name?

When you think of Manhattan Associates, you might think of an expensi...

Read more on Security

Cisco closes serious security vulnerability in Wireless LAN Controllers

Cisco closes serious security vulnerability in Wireless LAN Controllers

Cisco has fixed a vulnerability with the highest score in IOS XE Software for Wireless LAN Controllers. The p...

Mels Dees 2 days ago
LockBit ransomware group hit by data breach

LockBit ransomware group hit by data breach

The LockBit ransomware group has itself fallen victim to a data breach after its affiliate panels on the dark...

Mels Dees 3 days ago
Atos launches NIS2 application to streamline security compliance

Atos launches NIS2 application to streamline security compliance

Atos introduces the SecureHorizons NIS2 Compliance Manager, powered by ServiceNow. This new application repla...

Mels Dees 3 days ago
Cyber resilience needs to move beyond ‘not if, but when’
Top story

Cyber resilience needs to move beyond ‘not if, but when’

Don't break, but bend and do more prevention

Sander Almekinders May 7, 2025

Tech career

AI & Data Architect

Full time

Cloud Account Executive – Slack

Amsterdam Full time

Whitepapers

How to choose the right Enterprise Linux platform?

How to choose the right Enterprise Linux platform?

"A Buyer's Guide to Enterprise Linux" comprehensively analyzes the mo...

Try the latest high-end Synology backup system for free

Try the latest high-end Synology backup system for free

How do you ensure that your data is secure and can be quickly restore...

Enhance your data protection strategy for 2025

The Data Protection Guide 2025 explores the essential strategies and...

Strengthen your cybersecurity with DNS best practices

The white paper "DNS Best Practices" by Infoblox presents essential g...

Tech calendar

LambdaConf 2025

May 12, 2025 Estes Park

HPE AI Roadshow with NVIDIA

May 13, 2025 LIEMÈS, Utrecht

Qlik Connect 2025

May 13, 2025 Orlando

Red Hat Summit

May 19, 2025 Boston

Ontdek de kracht van Microsoft Copilot in het MBO

June 4, 2025 Schiphol

Kaseya DattoCon Europe

June 17, 2025 Dublin

Techzine Global

Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.

Follow us

Twitter
LinkedIn
YouTube

© 2025 Dolphin Publications B.V.
All rights reserved.

Techzine Service

  • Become a partner
  • Advertising
  • About Us
  • Contact
  • Terms & Conditions
  • Privacy Statement