Cyber firm Wiz says flaw could have led to mass exposure of Microsoft cloud customers


FILE PHOTO: A view shows a Microsoft logo at Microsoft offices in Issy-les-Moulineaux near Paris, France, March 25, 2024. REUTERS/Gonzalo Fuentes/File Photo

WASHINGTON, July 30 (Reuters) - ⁠Alphabet-owned cybersecurity company Wiz said on Thursday it had found a sweeping flaw ⁠that could have compromised Microsoft and thousands of its cloud customers.

Wiz said ‌in a post on its website that a now-patched vulnerability in a key Microsoft database service, Azure CosmosDB, would have allowed a hacker to remotely compromise any of its users.

In a statement, Microsoft said the problem ​had been "fully addressed" in cooperation with Wiz and that ⁠they had found "no evidence of customer ⁠impact based on our investigations."

Microsoft did not say how many customers could have been affected, ⁠but ‌CosmosDB is one of the pillars of Microsoft's cloud service offerings and is estimated to have thousands of customers.

It is used by companies to store ⁠data that helps services such as chatbots, web applications and ​online retail recommendation engines.Microsoft also ‌uses CosmosDB to power its own services, including Microsoft Teams and Copilot.

"When you ⁠build in ​the cloud, and when it's on Microsoft, it's usually in CosmosDB," said Ami Luttwak, Wiz chief technology officer.

The find is the latest in a series of vulnerabilities, including a similar CosmosDB flaw ⁠discovered by Wiz in 2021, that researchers say could ​have allowed the mass compromise of cloud users before it was patched.

Last year, researcher Dirk-jan Mollema discovered a flaw, also since patched, that could have allowed the mass hijacking of Microsoft ⁠cloud users' accounts.

Outside researchers said the flaw discovered by Wiz was serious.

"It's not good," said KarlFosaaen, a senior vice president at Minneapolis-based cybersecurity firm NetSpi. He said CosmosDB "does have some pretty heavy usage and there is frequently sensitive data that ends up in CosmosDB." ​But he cautioned that discoveries of this nature happened periodically ⁠across cloud services.

Vaisha Bernard, the co-owner of Dutch cybersecurity firm Eye Security, said researchers had ​recently been finding "a lot of high-severity cloud vulnerabilities at ‌infrastructure providers." And had a hacker found ​the one in CosmosDB before Wiz had, "they most definitely could have caused some pretty serious damage."

(Reporting by Raphael Satter; Editing by Jamie Freed and Louise Heavens)

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Others Also Read