Microsoft MFA AuthQuake-Fehler ermöglichte unbegrenzte Brute-Force-Versuche ohne Warnungen

Teilen:

Cybersecurity researchers have flagged a “critical” security vulnerability in Microsoft’s multi-factor authentication (MFA) implementation that allows an attacker to trivially sidestep the protection and gain unauthorized access to a victim’s account.

“The bypass was simple: it took around an hour to execute, required no user interaction and did not generate any notification or provide the account holder with any indication of trouble,” Oasis Security researchers Elad Luz and Tal Hason said in a report shared with The Hacker News.

Following responsible disclosure, the issue – codenamed AuthQuake – was addressed by Microsoft in October 2024.

While the Windows maker supports various ways to authenticate users via MFA, one method involves entering a six-digit code from an authenticator app after supplying the credentials. Up to 10 consequent failed attempts are permitted for a single session.

The vulnerability identified by Oasis, at its core, concerns a lack of rate limit and an extended time interval when providing and validating these one-time codes, thereby allowing a malicious actor to rapidly spawn new sessions and enumerate all possible permutations of the code (i.e., one million) without even alerting the victim about the failed login attempts.

It’s worth noting at this point that such codes, also referred to as time-based one-time passwords (TOTPs), are time-bound, wherein they are generated using the current time as a source of randomness. What’s more, the codes remain active only for a period of about 30 seconds, after which they are rotated.

“However, due to potential time differences and delays between the validator and the user, the validator is encouraged to accept a larger time window for the code,” Oasis pointed out. “In short, this means that a single TOTP code may be valid for more than 30 seconds.”

In the case of Microsoft, the New York-based company found the code to be valid for as long as 3 minutes, thus opening the door to a scenario where an attacker could take advantage of the extended time window to initiate more brute-force attempts simultaneously to crack the six-digit code.

“Introducing rate-limits and making sure they are properly implemented is crucial,” the researchers said. “Rate limits might not be enough, in addition – consequent failed attempts should trigger an account lock.”

Microsoft has since enforced a stricter rate limit that gets triggered after a number of failed attempts. Oasis also said the new limit lasts around half a day.

“The recent discovery of the AuthQuake vulnerability in Microsoft’s Multi-Factor Authentication (MFA) serves as a reminder that security isn’t just about deploying MFA – it must also be configured properly,” James Scobey, chief information security officer at Keeper Security, said in a statement.

“While MFA is undoubtedly a powerful defense, its effectiveness depends on key settings, such as rate limiting to thwart brute-force attempts and user notifications for failed login attempts. These features are not optional; they are critical for enhancing visibility, allowing users to spot suspicious activity early and respond swiftly.”

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:53 am, März 27, 2025
Wetter-Symbol 7°C
L: 6° | H: 8°
wenige Wolken
Luftfeuchtigkeit: 84 %
Druck: 1024 mb
Wind: 5 mph SSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 19%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:46 am
Sonnenuntergang: 6:24 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
6° | 8°°C 0 mm 0% 9 mph 90 % 1024 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
7° | 12°°C 1 mm 100% 13 mph 93 % 1015 mb 0 mm/h
Sa. März 29 9:00 pm
Wetter-Symbol
4° | 12°°C 0 mm 0% 9 mph 78 % 1023 mb 0 mm/h
So. März 30 9:00 pm
Wetter-Symbol
7° | 17°°C 0 mm 0% 10 mph 82 % 1024 mb 0 mm/h
Mo. März 31 9:00 pm
Wetter-Symbol
8° | 15°°C 0 mm 0% 8 mph 86 % 1028 mb 0 mm/h
Today 3:00 am
Wetter-Symbol
8° | 9°°C 0 mm 0% 4 mph 87 % 1024 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
8° | 8°°C 0 mm 0% 4 mph 90 % 1023 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 69 % 1023 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 7 mph 51 % 1021 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 9 mph 47 % 1018 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 7 mph 60 % 1017 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
12° | 12°°C 0 mm 0% 6 mph 78 % 1017 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 7 mph 82 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€81,141.96
-0.77%
Ethereum(ETH)
€1,876.50
-2.93%
Fesseln(USDT)
€0.93
-0.01%
XRP(XRP)
€2.21
-3.85%
Solana(SOL)
€128.30
-4.51%
USDC(USDC)
€0.93
0.00%
Dogecoin(DOGE)
€0.182540
1.16%
Shiba Inu(SHIB)
€0.000013
2.20%
Pepe(PEPE)
€0.000008
6.16%
Peanut das Eichhörnchen(PNUT)
€0.214428
7.85%
Nach oben scrollen