Skip to content
Techzine Europe
  • Home
  • Topstories
  • Topics
    • Analytics
    • Applications
    • Collaboration
    • Data Management
    • Devices
    • Devops
    • Infrastructure
    • Privacy & Compliance
    • Security
  • Insights
    • All Insights
    • Agentic AI
    • Analytics
    • Cloud ERP
    • Generative AI
    • IT in Retail
    • NIS2
    • RSAC 2025 Conference
    • Security Platforms
    • SentinelOne
  • More
    • Become a partner
    • About us
    • Contact us
    • Terms and conditions
    • Privacy Policy
  • Techzine Europe
  • Techzine Netherlands
Techzine News Security Serious Azure Active Directory vulnerability resolved by Microsoft
2 min Security

Serious Azure Active Directory vulnerability resolved by Microsoft

Erik van KlinkenJune 21, 2023 12:07 pmJune 21, 2023
Serious Azure Active Directory vulnerability resolved by Microsoft

Microsoft has fixed an exploit in Azure Active Directory (AD) authentication. The vulnerability allowed intruders to escalate account privileges and control the entire account.

Organizations deploy Azure AD to control user access. Examples include providing the backend for Office 365 users or centralising authentication between on-prem and cloud-based environments.

nOAuth

The misconfiguration has been called nOAuth by Descope, the party that discovered the vulnerability. AD OAuth applications that use email claims to generate access tokens are at risk. The process for exploitation sounds as simple as it is worrisome. A threat actor’s Azure AD admin account need only have a target’s email address for reference to log into a vulnerable application. From then on, privileges can be escalated, including lateral movement within the affected environment.

In a blog, Descope identifies where things went wrong with Azure AD’s configuration. The email claim is mutable and does not require authentication to count as an identifier. Microsoft already discouraged users from using email for login, according to Descope.

Vulnerable

Descope does not name the targets by name, but speaks of “several major applications” that were exploited. This included a design app with millions of monthly users, a publicly traded customer experience company and a multi-cloud consulting firm. Administrators of vulnerable applications can turn to Descope’s “Suggested remediation steps” for help.

Given Azure AD’s massive market share within the identity and access management world (27.53 percent according to 6sense), such a vulnerability could potentially do a considerable amount of damage. However, Microsoft has already contacted vulnerable parties behind the scenes after it received word from Descope about the exploit on April 11.

Also read: Microsoft Bing penetrated through misconfiguration in Azure Active Directory

Tags:

account privileges / Azure Active Directory / vulnerability

"*" indicates required fields

Stay tuned, subscribe!

Nieuwsbrieven*
This field is for validation purposes and should be left unchanged.

Related

Exploit details of serious Cisco IOS XE vulnerability now public

Microsoft makes Azure AI Foundry available with improved model tools

Chrome vulnerability allowing account takeover fixed

Microsoft expands fine-tuning capabilities in Azure AI Foundry

Editor picks

Google Cloud problem causes global outage

Several online services were shut down on Thursday evening due to an ...

SAP CEO calls European plan for own cloud data centers completely crazy

The CEO of SAP, Europe's most valuable company, believes it is pointl...

Goodbye AIOps, hello AgenticOps: what is it and what can you do with it?

People and machines come together in Cisco AI Canvas

Lemon predicts sour faces over AI coding tools

Developer-skills and talent company Lemon thinks it has a handle on w...

Insight: Storage

It’s World Backup Day, but backups alone are not enough

It started as a Reddit post in 2011: World Backup Day. Every March 31...

Rubrik expands to AWS, Oracle Cloud Infrastructure and OpenShift

From now on, Rubrik is expanding and debuting its protection and back...

Storage is complex: think carefully about what you need

Storage is complex: think carefully about what you need

Complexity can make arranging storage difficult. Still, as an organiz...

NetApp refreshes high-end AFF A-Series: all-flash for AI

NetApp refreshes high-end AFF A-Series: all-flash for AI

NetApp's all-flash portfolio is doing very well. Last year it grew by...

Read more on Security

Zero-click attack reveals new AI vulnerability

Zero-click attack reveals new AI vulnerability

Echoleak is a new attack vector that exploits AI assistants by subtly manipulating prompts. The attack was ex...

Berry Zwets 2 days ago
DNS analysis reveals links between VexTrio and WordPress hackers

DNS analysis reveals links between VexTrio and WordPress hackers

New findings from Infoblox show that WordPress hackers and Traffic Distribution System operators associated w...

Berry Zwets 2 days ago
How a fake cybersecurity firm became a real threat
Expert Talks

How a fake cybersecurity firm became a real threat

The Job Offer You Can’t Believe (And Probably Shouldn't)

Javvad Malik 2 days ago
Microsoft launches free European Security Program: what does it entail?
Top story

Microsoft launches free European Security Program: what does it entail?

Microsoft President Brad Smith is living up to his political-sounding job title. After a series of appearance...

Erik van Klinken June 5, 2025

Whitepapers

How to choose the right Enterprise Linux platform?

How to choose the right Enterprise Linux platform?

"A Buyer's Guide to Enterprise Linux" comprehensively analyzes the mo...

Try the latest high-end Synology backup system for free

Try the latest high-end Synology backup system for free

How do you ensure that your data is secure and can be quickly restore...

Enhance your data protection strategy for 2025

The Data Protection Guide 2025 explores the essential strategies and...

Strengthen your cybersecurity with DNS best practices

The white paper "DNS Best Practices" by Infoblox presents essential g...

Tech calendar

Kaseya DattoCon Europe

June 17, 2025 Dublin

Nutanix Cloud Day Nederland 2025

June 17, 2025 Zeist

Akamai Customer Day Benelux

June 18, 2025 Nieuwegein

Nürnberg Digital Festival 2025

June 30, 2025 Nürnberg

GITEX DIGI_HEALTH 5.0 - Thailand

September 10, 2025 BITEC Bangkok, Thailand

IT Arena

September 26, 2025 Lviv, Ukraine

Techzine Global

Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.

Follow us

Twitter
LinkedIn
YouTube

© 2025 Dolphin Publications B.V.
All rights reserved.

Techzine Service

  • Become a partner
  • Advertising
  • About Us
  • Contact
  • Terms & Conditions
  • Privacy Statement