Researchers Crack Microsoft Azure MFA in an Hour

Teilen:

A critical flaw in the company’s rate limit for failed sign-in attempts allowed unauthorized access to a user account, including Outlook emails, OneDrive files, Teams chats, Azure Cloud, and more.

Researchers cracked a Microsoft Azure method for multifactor authentication (MFA) in about an hour, due to a critical vulnerability that allowed them unauthorized access to a user’s account, including Outlook emails, OneDrive files, Teams chats, Azure Cloud, and more.

Researchers at Oasis Security discovered the flaw, which was present due to a lack of rate limit for the amount of times someone could attempt to sign in with MFA and fail when trying to access an account, they revealed in a blog post on Dec. 11. The flaw exposed the more than 400 million paid Microsoft 365 seats to potential account takeover, they said.

When signing into a Microsoft account, a user supplies their email and password and then selects a pre-configured MFA method. In the case used by the researchers, they are given a code by Microsoft via another form of communication to facilitate sign-in.

The researchers achieved the bypass, which they dubbed “AuthQuake,” by “rapidly creating new sessions and enumerating codes,” Tal Hason, an Oasis research engineer, wrote in the post. This allowed them to demonstrate “a very high rate of attempts that would quickly exhaust the total number of options for a 6-digit code,” which is 1 million, he explained.

“Simply put — one could execute many attempts simultaneously,” Hason wrote. Moreover, during the multiple failed attempts to sign in, account owners did not receive any alert about the activity, “making this vulnerability and attack technique dangerously low profile,” Hason wrote.

Oasis informed Microsoft of the issue, which acknowledged its existence in June and fixed it permanently by Oct. 9, the researchers said. “While specific details of the changes are confidential, we can confirm that Microsoft introduced a much stricter rate limit that kicks in after a number of failed attempts; the strict limit lasts around half a day,” Hason wrote.

Elisabeth Montalbano

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:49 am, Jan. 24, 2025
Wetter-Symbol 9°C
L: 9° | H: 10°
overcast clouds
Luftfeuchtigkeit: 92 %
Druck: 996 mb
Wind: 11 mph SW
Windböe: 18 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 6 km
Sonnenaufgang: 7:49 am
Sonnenuntergang: 4:35 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
9° | 10°°C 1 mm 100% 24 mph 91 % 1002 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 5°°C 1 mm 100% 11 mph 90 % 1010 mb 0 mm/h
So. Jan. 26 9:00 pm
Wetter-Symbol
2° | 7°°C 1 mm 100% 15 mph 97 % 1009 mb 0 mm/h
Mo. Jan. 27 9:00 pm
Wetter-Symbol
6° | 8°°C 1 mm 100% 12 mph 98 % 991 mb 0 mm/h
Di. Jan. 28 9:00 pm
Wetter-Symbol
5° | 7°°C 1 mm 100% 15 mph 92 % 999 mb 0 mm/h
Today 3:00 am
Wetter-Symbol
9° | 10°°C 0.83 mm 83% 22 mph 91 % 996 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
9° | 10°°C 1 mm 100% 24 mph 89 % 995 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
10° | 11°°C 1 mm 100% 15 mph 85 % 994 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
9° | 9°°C 0.8 mm 80% 17 mph 60 % 997 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 13 mph 50 % 999 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
7° | 7°°C 0 mm 0% 9 mph 56 % 1002 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 5 mph 63 % 1002 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 68 % 1000 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€99,159.01
0.87%
Ethereum(ETH)
€3,172.44
2.68%
XRP(XRP)
€2.95
-2.23%
Fesseln(USDT)
€0.96
0.06%
Solana(SOL)
€239.70
0.62%
USDC(USDC)
€0.96
0.00%
Dogecoin(DOGE)
€0.331925
-2.26%
Shiba Inu(SHIB)
€0.000019
-1.63%
Pepe(PEPE)
€0.000014
-0.42%
Peanut das Eichhörnchen(PNUT)
€0.333452
-4.27%
Nach oben scrollen