Industry Insights

Blog, Security

Nasty Vulnerability Found in Microsoft Azure’s Managed Database Service

by | Monday, September 27th, 2021

Some vulnerabilities can fly under the radar for quite some time, some for months or even years. This is the case with a recently discovered Microsoft Azure database vulnerability. The exploit, discovered by cloud security provider Wiz, is found in Cosmos DB, Microsoft Azure’s managed database service, and it’s a real nasty one at that. Let’s dive into the details and see what we can learn from the incident.

This vulnerability, aptly titled Chaos DB, is so deeply rooted that it can grant read/write access for every single database on the service. While there is no evidence that the exploit was utilized, that’s not to say that this isn’t a huge problem. It all boils down to the way that the database handles primary keys and, once again, how Microsoft deployed default settings for one of their services.

Wiz discovered this vulnerability in the Jupyter Notebook feature of Cosmos DB. This feature was enabled automatically for all instances of Cosmos DB in February of 2021, but Wiz suspects that this particular issue could go all the way back to 2019 when Jupyter was first introduced. Basically, what happens is that a misconfiguration within Jupyter allows users to obtain the primary keys for other users of Cosmos DB. This is perhaps the worst possible outcome, as the primary key gives the holder the ability to read, write, and delete data on just about anyone’s database.

Since the primary keys do not expire, if they have been leaked to malicious threat actors, the only solution is to rotate the primary keys so that they are not useful to whoever gains access to them. If this is not done, then anyone who has obtained the primary key will have all of these escalated privileges. Wiz, on the other hand, recommends that organizations who have had Jupyter enabled on their service for any amount of time rotate their keys… you know, just to be safe.

Thankfully, Microsoft disabled the vulnerability that enabled Chaos DB promptly after it was discovered, but there is only so much that the company can do in terms of the primary keys, which customers are going to have to rotate themselves. Microsoft issued a warning to the affected customers—about a third of the service’s user base—and sent out instructions on how to mitigate the risk, so any users of this service should catch up on the state of the problem. 

Again, we want to emphasize the importance of making sure that your business’ technology is configured correctly—especially when incidents like these occur. You never know when one minor setting could expose your critical data to hackers and other online threats. If you want to take the guesswork out of the equation, Compudata is happy to lend its support. We can assist your organization with implementing and configuring any business technology solution. To learn more, reach out to us at 1-855-405-8889.

A Glimpse Into What Compliance Looks Like for Businesses

It’s easy to see all the reasons why you should make data regulations and compliance a priority. After all, you want to ensure you don’t violate the trust and security of your customers, as well as the integrity of your operations. If you make even one mistake, it...

AI Search Isn’t There Yet

People do this all the time: if they don’t know an answer, they just make something up that sounds right. It turns out AI has the same bad habit. A Study Put AI Search to the Test, and It Did Not Go Well Researchers at the Tow Center for Digital Journalism (part of...

Remote Work Is Great, but There Are Some Pitfalls

Do you have employees working remotely? If you do, the real question is, are you doing everything you can to keep them productive and secure? Remote work is awesome, but it comes with its fair share of risks. Today, we get into how to competently confront them. Remote...

Hiring IT is Hard (Here’s How to Make It Easier)

Do you have someone on your staff who can handle most IT-related issues for your business? If not, we’re sure your organization feels it in more ways than one. The issues that come from not having IT help are only made more frustrating when it comes time to find IT...

Let’s Take the Lid Off of CAPTCHA

We've officially reached the point where humans have to prove they're, well, human just to access websites. One of the most common ways to do this? CAPTCHA. CAPTCHA stands for Completely Automated Public Turing test to tell Computers and Humans Apart. It might sound...

Automation Isn’t Always the Best Business Option

Automation makes sense from an operations standpoint, and people see this despite the many who advocate for scaling back to save jobs. For every task that can be completed, however, less than half can be automated. When you consider all the tasks that a human might be...

More Reading from Industry Insights:

AI Search Isn’t There Yet

People do this all the time: if they don’t know an answer, they just make something up that sounds right. It turns out AI has the same bad habit. A Study Put AI Search to the Test, and It Did Not Go Well Researchers at the Tow Center for Digital Journalism (part of...

Hiring IT is Hard (Here’s How to Make It Easier)

Do you have someone on your staff who can handle most IT-related issues for your business? If not, we’re sure your organization feels it in more ways than one. The issues that come from not having IT help are only made more frustrating when it comes time to find IT...