Skip to content
Techzine Global
  • Home
  • Topstories
  • Topics
    • Analytics
    • Applications
    • Collaboration
    • Data Management
    • Devices
    • Devops
    • Infrastructure
    • Privacy & Compliance
    • Security
  • Insights
    • All Insights
    • Agentic AI
    • Analytics
    • Cloud ERP
    • Generative AI
    • IT in Retail
    • NIS2
    • RSAC 2025 Conference
    • Security Platforms
    • SentinelOne
  • More
    • Become a partner
    • About us
    • Contact us
    • Terms and conditions
    • Privacy Policy
  • Techzine Global
  • Techzine Netherlands
  • Techzine Belgium
  • Techzine TV
  • ICTMagazine Netherlands
  • ICTMagazine Belgium
Techzine » News » Security » Serious Azure Active Directory vulnerability resolved by Microsoft
2 min Security

Serious Azure Active Directory vulnerability resolved by Microsoft

Erik van KlinkenJune 21, 2023 12:07 pmJune 21, 2023
Serious Azure Active Directory vulnerability resolved by Microsoft

Microsoft has fixed an exploit in Azure Active Directory (AD) authentication. The vulnerability allowed intruders to escalate account privileges and control the entire account.

Organizations deploy Azure AD to control user access. Examples include providing the backend for Office 365 users or centralising authentication between on-prem and cloud-based environments.

nOAuth

The misconfiguration has been called nOAuth by Descope, the party that discovered the vulnerability. AD OAuth applications that use email claims to generate access tokens are at risk. The process for exploitation sounds as simple as it is worrisome. A threat actor’s Azure AD admin account need only have a target’s email address for reference to log into a vulnerable application. From then on, privileges can be escalated, including lateral movement within the affected environment.

In a blog, Descope identifies where things went wrong with Azure AD’s configuration. The email claim is mutable and does not require authentication to count as an identifier. Microsoft already discouraged users from using email for login, according to Descope.

Vulnerable

Descope does not name the targets by name, but speaks of “several major applications” that were exploited. This included a design app with millions of monthly users, a publicly traded customer experience company and a multi-cloud consulting firm. Administrators of vulnerable applications can turn to Descope’s “Suggested remediation steps” for help.

Given Azure AD’s massive market share within the identity and access management world (27.53 percent according to 6sense), such a vulnerability could potentially do a considerable amount of damage. However, Microsoft has already contacted vulnerable parties behind the scenes after it received word from Descope about the exploit on April 11.

Also read: Microsoft Bing penetrated through misconfiguration in Azure Active Directory

Tags:

account privileges / Azure Active Directory / vulnerability

"*" indicates required fields

Stay tuned, subscribe!

Nieuwsbrieven*
This field is for validation purposes and should be left unchanged.

Related

SharePoint vulnerability actively exploited: Microsoft rolls out emergency patches

Exploit details of serious Cisco IOS XE vulnerability now public

Microsoft makes Azure AI Foundry available with improved model tools

Chrome vulnerability allowing account takeover fixed

Editor picks

NIS2 is intended to make organizations more secure, but will it succeed?

NIS2 hasn't been converted into national law in every EU country, des...

Dutch lab paid off cybercriminals, but full-scale data leak looms

The Nova hacker group already received a ransom payment from its vict...

Printers play a central role in HP’s workplace vision

Innovation in software, AI, and security

Intel’s CEO survives baptism of fire, will his company do the same?

US President Donald Trump appears to have changed his mind. Having ca...

Techzine.tv

What is HPE VM Essentials and is it a direct competitor to VMware?

What is HPE VM Essentials and is it a direct competitor to VMware?

Managing the AI chaos with ServiceNow's AI Control Tower

Managing the AI chaos with ServiceNow's AI Control Tower

The impact of OpsRamp on HPE and its integration into the stack

The impact of OpsRamp on HPE and its integration into the stack

SAP Sapphire Orlando: Unveiling a new pricing strategy

SAP Sapphire Orlando: Unveiling a new pricing strategy

Read more on Security

Orange Belgium reports cyberattack: 850,000 accounts compromised

Orange Belgium reports cyberattack: 850,000 accounts compromised

Telecom operator Orange Belgium was the victim of a cyberattack at the end of July, in which hackers gained a...

Erik van Klinken 8 hours ago
Zscaler and CrowdStrike deepen SecOps collaboration

Zscaler and CrowdStrike deepen SecOps collaboration

Zscaler and CrowdStrike have expanded their partnership. This comes shortly after Zscaler's definitive acquis...

Erik van Klinken 6 hours ago
The many victims of Salesforce attacker ShinyHunters
Top story

The many victims of Salesforce attacker ShinyHunters

Google, Cisco, Air France-KLM, Chanel...

Erik van Klinken August 7, 2025
NIS2 is intended to make organizations more secure, but will it succeed?
Top story

NIS2 is intended to make organizations more secure, but will it succeed?

NIS2 hasn't been converted into national law in every EU country, despite the deadline set for October 2024. ...

Erik van Klinken 3 days ago

Expert Talks

Meeting future workload demands: the case for emerging memory technologies

Meeting future workload demands: the case for emerging memory technologies

It often feels as though memory is an outlier in the technology world...

How AI and automation are redefining ROI in the enterprise

How AI and automation are redefining ROI in the enterprise

Today’s data and business analysts are equipped with a wide array o...

Enhancing video encoding: The AV1 support in the new ARTPEC-9 System-on-Chip

In an era where video security and digital technologies are evolving ...

Simplifying complexity: Bridging the cloud skills gap

In recent years, there has been a seismic shift away from traditional...

Tech calendar

NULLCON Berlin 2025

September 4, 2025 Courtyard By Marriott, Berlin City Center

bit summit

September 4, 2025 Hamburg

GITEX DIGI_HEALTH 5.0 - Thailand

September 10, 2025 BITEC Bangkok, Thailand

VeeamON Tour 2025

September 18, 2025 Driebergen-Rijsenburg

IT Arena

September 26, 2025 Lviv, Ukraine

Innovation Week 2025

October 9, 2025 Prague

Whitepapers

Experience Synology’s latest enterprise backup solution

Experience Synology’s latest enterprise backup solution

How do you ensure your company data is both secure and quickly recove...

How to choose the right Enterprise Linux platform?

How to choose the right Enterprise Linux platform?

"A Buyer's Guide to Enterprise Linux" comprehensively analyzes the mo...

Enhance your data protection strategy for 2025

The Data Protection Guide 2025 explores the essential strategies and...

Strengthen your cybersecurity with DNS best practices

The white paper "DNS Best Practices" by Infoblox presents essential g...

Techzine Global

Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.

Follow us

Twitter
LinkedIn
YouTube

© 2025 Dolphin Publications B.V.
All rights reserved.

Techzine Service

  • Become a partner
  • Advertising
  • About Us
  • Contact
  • Terms & Conditions
  • Privacy Statement