Microsoft has documented and mitigated AutoWarp -- a critical Microsoft Azure cloud vulnerability discovered by Orca Security.Orca discovered and disclosed the vulnerability to Microsoft in December 2021. Within four days of the initial communications between the two companies, Microsoft had fixed the issue and started looking for additional variants of the attack vector. Orca disclosed deeper details about the former vulnerability on March 7, 2022.To reiterate: Microsoft has closed the vulnerability. As an extra step, the company also recommends that its Azure Automation customers follow these Security best practices.
Microsoft Azure Automation: The Cloud Vulnerability (Now Fixed)
The vulnerability involved Microsoft Azure Automation, which allows customers to execute automation code in a managed fashion, Orca noted. Among the details the security company shared:- Each customer’s automation code runs inside a sandbox, isolated from other customers’ code executing on the same virtual machine, Orca said.
- However, Orca discovered a "serious flaw that allowed us to interact with an internal server that manages the sandboxes of other customers. We managed to obtain authentication tokens for other customer accounts through that server. Someone with malicious intentions could’ve continuously grabbed tokens, and with each token, widen the attack to more Azure customers."




