Mmastodon TechnologyCybersecurity first seen 21 h ago, last 21 h ago, peak #12
Microsoft fixes severe cloud flaws in October security bundle
Original: Microsoft October bundle — CVSS 10.0 cert bypass in Partner Center, 9.9 authz bypass in Bookings, two unauth RCEs at 9.8
Microsoft's October patch bundle addresses a string of critical flaws in its hosted services: a CVSS 10.0 certificate bypass in Partner Center, a 9.9 authorization bypass in Bookings, two unauthenticated remote code execution vulnerabilities rated 9.8 in Azure App Service and Dataverse, and a 9.6 privilege escalation in Azure SRE Agent. Microsoft patches the backend automatically, but security practitioners urge tenants to verify their configurations.
Why now: The exceptional severity ratings and the fact that many flaws affect managed cloud services where customers cannot patch directly are drawing attention from the security community.
MicrosoftAzure App ServiceDataversePartner CenterMicrosoft Bookings
Evidence
- Microsoft October bundle — CVSS 10.0 cert bypass in Partner Center, 9.9 authz bypass in Bookings, two unauth RCEs at 9.8 in Azure App Service and Dataverse, 9.6 privesc in Azure SRE Agent. All hosted services. Microsoft patches the backend. Verify your tenant configs and… · threataft@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/1556576