Chrome 112 Patches 16 Security Flaws

Google this week announced the release of Chrome 112 in the stable channel with patches for 16 vulnerabilities, including 14 reported by external researchers.

Of the externally reported flaws, two are rated ‘high severity’, nine have a severity rating of ‘medium’, while the remaining three are low-severity issues.

The most severe of these is a heap buffer overflow bug in Visuals. Tracked as CVE-2023-1810, the vulnerability earned the reporting researcher a $5,000 bug bounty reward.

“CVE-2023-1810 can allow a compromised renderer to register multiple things with the same FrameSinkId, violating ownership assumptions,” Action1 VP Mike Walters said in an emailed comment. 

Next in line is a use-after-free flaw in Frames, which is tracked as CVE-2023-1811, and for which Google awarded a $3,000 bug bounty. The issue, Walters says, could lead to a crash or malicious code execution.

Next in line is a use-after-free flaw in Frames, which is tracked as CVE-2023-1811, and for which Google awarded a $3,000 bug bounty.

The resolved medium-severity vulnerabilities include out-of-bounds memory access, inappropriate implementation, insufficient validation of untrusted input, use-after-free, incorrect security UI, insufficient policy enforcement, out-of-bounds read, and heap buffer overflow issues.

Impacted Chrome components include DOM Bindings, Extensions, Safe Browsing, Networking APIs, Picture In Picture, Intents, Vulkan, Accessibility, and Browser History.

The three low-severity flaws addressed with the Chrome 112 release impact the WebShare, Navigation, FedCM components.

Google says it has paid roughly $26,000 in bug bounty rewards for the reported vulnerabilities, but the final amount might be higher, as the internet giant has yet to determine the amount to be handed out for two of the bugs.

Per Google’s policies, no rewards will be issued for two other vulnerabilities, which were reported by Microsoft researchers.

Google makes no mention of any of these vulnerabilities being exploited in attacks.

The latest Chrome iteration is now rolling out as version 112.0.5615.49/50 for Windows and as version 112.0.5615.49 for Linux and macOS.

Related: Chrome 111 Update Patches High-Severity Vulnerabilities

Related:Google Discontinuing Chrome Tool for Removing Unwanted Software

Related: Chrome 111 Patches 40 Vulnerabilities

https://www.securityweek.com/chrome-112-patches-16-security-flaws/




Android’s April 2023 Updates Patch Critical Remote Code Execution Vulnerabilities

Google this week announced the April 2023 security updates for Android devices, with patches for over 65 vulnerabilities, including two critical bugs leading to remote code execution (RCE).

Google’s Android security bulletin for April 2023 describes 26 vulnerabilities resolved in the Framework and System components as part of the 2023-04-01 security patch level. Most of these are high-severity flaws leading to elevation of privilege (EoP) or information disclosure.

Two of the 16 issues addressed in System, however, are critical-severity RCE bugs, tracked as CVE-2023-21085 and CVE-2023-21096.

“The most severe of these issues is a critical security vulnerability in the System component that could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation,” Google explains.

The second part of Android’s April 2023 security update arrives on devices as the 2023-04-05 security patch level and includes fixes for 40 vulnerabilities in kernel, Arm, Imagination Technologies, MediaTek, Unisoc, and Qualcomm components.

While most of these bugs are rated ‘high severity’, four of the issues impacting Qualcomm components are considered ‘critical severity’.

For the second month in the row, Google has not published a Pixel security bulletin on the same day that it announced the Android patches. However, Pixel users did receive an update in March, although they had to wait a few more days for it to arrive.

No Android Automotive OS security patches were announced this month either.

Related:Android’s March 2023 Updates Patch Over 50 Vulnerabilities

Related: Google Describes Privacy, Security Improvements in Android 14

Related:Android’s February 2023 Updates Patch 40 Vulnerabilities

https://www.securityweek.com/androids-april-2023-updates-patch-critical-remote-code-execution-vulnerabilities/




Nexx Ignores Vulnerabilities Allowing Hackers to Remotely Open Garage Doors

Texas-based smart home product provider Nexx appears to have ignored repeated attempts to report serious vulnerabilities that can be exploited by hackers to remotely open garage doors, and take control of alarms and smart plugs. 

Nexx offers smart alarms, garage door controllers, and smart plugs, all of which can be controlled remotely from a dedicated mobile application. 

Researcher Sam Sabetan discovered that these products are affected by serious vulnerabilities in late 2022 and disclosed their details on Tuesday. 

The US Cybersecurity and Infrastructure Security Agency (CISA) has also released an advisory to warn individuals and organizations using Nexx products about the flaws identified by the researcher. The agency said the impacted products are used by commercial facilities worldwide.

Sabetan and CISA said their attempts to report the vulnerabilities to Nexx were ignored. SecurityWeek has also reached out to Nexx for comment.

The researcher has discovered five types of vulnerabilities, most of which have been assigned ‘high’ or ‘critical’ severity ratings. The list of issues includes the use of hardcoded credentials, authorization bypass flaws that can be leveraged to execute unauthorized actions, information disclosure issues, and improper authentication.

In a real world attack scenario, an attacker can exploit these vulnerabilities to open or close garage doors remotely over the internet, hijack any alarm system, and turn on/off smart plugs connected to household appliances. 

In order to conduct an attack, the hacker only needs the targeted user’s device ID, email address, name, or MAC address, depending on the type of device they are targeting.  

A video demo made by the researcher shows how a hacker can obtain the information of hundreds of users.

[embedded content]

“It is estimated that over 40,000 devices, located in both residential and commercial properties, are impacted. Furthermore, I determined that more than 20,000 individuals have active Nexx accounts,” Sabetan explained. 

Related: Aiphone Intercom System Vulnerability Allows Hackers to Open Doors

Related: Vulnerabilities in HID Mercury Access Controllers Allow Hackers to Unlock Doors

Related: Nuki Smart Lock Vulnerabilities Allow Hackers to Open Doors

Related: Vulnerability in IDEMIA Biometric Readers Allows Hackers to Unlock Doors

https://www.securityweek.com/nexx-ignores-vulnerabilities-allowing-hackers-to-remotely-open-garage-doors/




Zimbra Flaw Exploited by Russia Against NATO Countries Added to CISA ‘Must Patch’ List

The US Cybersecurity and Infrastructure Security Agency (CISA) has added to its ‘Must Patch’ list a Zimbra vulnerability exploited by Russian hackers in attacks targeting NATO countries.

The flaw, tracked as CVE-2022-27926 (CVSS score of 6.1), is described as a reflected cross-site scripting (XSS) bug in Zimbra Collaboration version 9.0.

Because of this issue, an endpoint URL may accept parameters without sanitization, which could allow an unauthenticated attacker to provide crafted request parameters leading to the execution of arbitrary web scripts or HTML code.

While CISA does not provide details on the observed exploitation of CVE-2022-27926, the agency’s warning comes only days after a Proofpoint report on the vulnerability being exploited by Russia-linked advanced persistent threat (ATP) actor Winter Vivern in attacks targeting NATO countries.

Also tracked as TA473, Winter Vivern has been observed launching cyberattacks in support of Russian and/or Belarussian geopolitical goals in the context of the Russia-Ukraine war.

The attacks against NATO countries targeted public Zimbra hosted webmail portals to access email correspondence of military, government, and diplomatic organizations in Europe.

The APT uses scanning tools to identify vulnerable, unpatched webmail portals and then sends phishing emails containing a malicious a URL leading to the execution of JavaScript code that in turns downloads a next stage JavaScript payload to conduct cross-site request forgery (CSRF) attacks and capture victims’ credentials.

According to Proofpoint, Winter Vivern appears to have invested time and resources in analyzing the publicly exposed webmail portals of the targeted organizations in order to create different JavaScript payloads for each of them.

“These labor-intensive customized payloads allow actors to steal usernames, passwords, and store active session and CSRF tokens from cookies facilitating the login to publicly facing webmail portals belonging to NATO-aligned organizations,” Proofpoint explains.

Organizations are advised to upgrade to a patched version of the Zimbra Collaboration Suite as soon as possible.

Per Binding Operational Directive (BOD) 22-01, once a vulnerability is added to CISA’s Known Exploited Vulnerabilities catalog, federal agencies have three weeks to apply the relevant patches within their environments.

Related: Microsoft: 17 European Nations Targeted by Russia in 2023 as Espionage Ramping Up

Related: New Espionage Group ‘YoroTrooper’ Targeting Entities in European, CIS Countries

Related: Leaked Documents Detail Russia’s Cyberwarfare Tools, Including for OT Attacks

https://www.securityweek.com/zimbra-flaw-exploited-by-russian-hackers-against-nato-added-to-cisa-must-patch-list/




Elementor Pro Plugin Vulnerability Exploited to Hack WordPress Websites

A severe vulnerability in the Elementor Pro plugin is being exploited to hack WordPress websites, WordPress security company Patchstack warns.

Described as a broken access control issue, the flaw can be exploited on vulnerable websites with the WooCommerce plugin installed to change any WordPress setting. An attacker would need to be authenticated as a low-privileged user, such as subscriber or customer, to exploit the bug.

“This is done through an AJAX action of Elementor Pro that does not have proper privilege control in place,” Patchstack explains.

According to the security firm, the flaw allows an attacker to enable the registration page of a website and set the default user role to administrator.

The attacker can then create a new user account that has administrator privileges, which allows them to either redirect the site to a malicious domain, or inject malicious code, such as a plugin with a backdoor.

“From what we have seen so far, hackers who exploit this vulnerability either update the URL of the site to a malicious domain so visitors get redirected to this malicious domain, or the hackers upload a fake plugin which contains a backdoor. This backdoor may be activated and communicated with right away or at a future date,” Patchstack told SecurityWeek.

The company says it has observed malicious attacks targeting this vulnerability originating from multiple IP addresses, with attackers injecting malicious .zip and .php files.

The flaw, which has a CVSS score of 8.8, but no CVE identifier yet, was addressed on March 22, with the release of Elementor Pro version 3.11.7, which ‘improved code security enforcement in WooCommerce components’.

Elementor Pro users are advised to update to a patched version of the plugin as soon as possible.

With over 5 million active installations, the Elementor plugin is a popular drag-and-drop website builder designed for creating websites without having to write code. The paid version of the plugin, Elementor Pro, provides additional features and tools for site building.

Elementor’s developers also run a bug bounty program on the Bugcrowd platform.

Related:Critical Vulnerability in Elementor Plugin Impacts Millions of WordPress Sites

Related:Critical WooCommerce Payments Vulnerability Leads to Site Takeover

Related: Vulnerability in Popular Real Estate Theme Exploited to Hack WordPress Websites

https://www.securityweek.com/elementor-pro-plugin-vulnerability-exploited-to-hack-wordpress-websites/




US Defense Department Launches ‘Hack the Pentagon’ Website

The US Department of Defense (DoD) has launched a new website to help organizations within the department to launch bug bounty programs and recruit security researchers.

The new Hack the Pentagon (HtP) website, launched by the Chief Digital and Artificial Intelligence Office (CDAO) Directorate for Digital Services (DDS), is meant as a companion for the DoD’s long-running bug bounty program with the same name.

Initially launched in 2016, the DoD’s bug bounty program has resulted in more than 1,600 white hat hackers reporting over 2,100 vulnerabilities in Pentagon systems and assets and earning over $650,000 in bounty payments.

Vetted security researchers have identified issues in networks, in planes, next-generation secure hardware, power and HVAC systems, water facilities, and more.

“DDS built the HtP website as a resource for Department of Defense organizations, vendors, and security researchers to learn how to conduct a bug bounty, partner with the CDAO DDS team to support bug bounties, and participate in DoD-wide bug bounties,” DoD says.

Previously, the DoD’s bug bounty program ran on a project-by-project basis, but the new website will help the department run continuous programs, offering access to lessons learned and best practices, and helping DoD organizations recruit security researchers for their bug bounty programs.

To date, the DoD has run more than 40 bug bounty projects, including Hack the Pentagon (at its third installment this year), Hack the Air Force, Hack the Army, Hack the Marine Corps, Hack the Defense Travel System, Hack DHS, and Hack US.

Related: DoD Announces Results of Vulnerability Disclosure Program for Defense Contractors

Related: U.S. Government Announces ‘Hack the Army 3.0’ Bug Bounty Program

Related: Pentagon Paid Out $290,000 for Vulnerabilities in Air Force Data Center

https://www.securityweek.com/us-defense-department-launches-hack-the-pentagon-website/




Hackers exploit WordPress plugin flaw that gives full control of millions of sites

Hackers exploit WordPress plugin flaw that gives full control of millions of sites
Getty Images

Hackers are actively exploiting a critical vulnerability in a widely used WordPress plugin that gives them the ability to take complete control of millions of sites, researchers said.

The vulnerability, which carries a severity rating of 8.8 out of a possible 10, is present in Elementor Pro, a premium plugin running on more than 12 million sites powered by the WordPress content management system. Elementor Pro allows users to create high-quality websites using a wide range of tools, one of which is WooCommerce, a separate WordPress plugin. When those conditions are met, anyone with an account on the site—say a subscriber or customer—can create new accounts that have full administrator privileges.

The vulnerability was discovered by Jerome Bruandet, a researcher with security firm NinTechNet. Last week, Elementor, the developer of the Elementor Pro plugin, released version 3.11.7, which patched the flaw. In a post published on Tuesday, Bruandet wrote:

An authenticated attacker can leverage the vulnerability to create an administrator account by enabling registration (users_can_register) and setting the default role (default_role) to “administrator”, change the administrator email address (admin_email) or, as shown below, redirect all traffic to an external malicious website by changing siteurl among many other possibilities:

MariaDB [example]> SELECT * FROM `wp_options` WHERE `option_name`='siteurl';
+-----------+-------------+------------------+----------+
| option_id | option_name | option_value | autoload |
+-----------+-------------+------------------+----------+
| 1 | siteurl | https://evil.com | yes |
+-----------+-------------+------------------+----------+
1 row in set (0.001 sec)

Now, researchers with a separate security firm, PatchStack, report that the vulnerability is under active exploitation. Attacks are coming from a variety of IP addresses, including:

  • 193.169.194.63
  • 193.169.195.64
  • 194.135.30.6

Files uploaded to compromised sites often have the following names:

  • wp-resortpack.zip
  • wp-rate.php
  • lll.zip

URLs of compromised sites are often being changed to:

  • away[dot]trackersline[dot]com

The broken access control vulnerability stems from Elementor Pro’s use of the “elementor-pro/modules/woocommerce/module.php” component. When WooCommerce is running, this script registers the following AJAX actions:

/** * Register Ajax Actions. * * Registers ajax action used by the Editor js. * * @since 3.5.0 * * @param Ajax $ajax */
public function register_ajax_actions( Ajax $ajax ) { // `woocommerce_update_page_option` is called in the editor save-show-modal.js. $ajax->register_ajax_action( 'pro_woocommerce_update_page_option', [ $this, 'update_page_option' ] ); $ajax->register_ajax_action( 'pro_woocommerce_mock_notices', [ $this, 'woocommerce_mock_notices' ] );
}

and

/** * Update Page Option. * * Ajax action can be used to update any WooCommerce option. * * @since 3.5.0 * * @param array $data */
public function update_page_option( $data ) { update_option( $data['option_name'], $data['editor_post_id'] );
}

The update_option function “is supposed to allow the Administrator or the Shop Manager to update some specific WooCommerce options, but user input aren’t validated and the function lacks a capability check to restrict its access to a high privileged user only,” Bruandet explained. He continued:

Elementor uses its own AJAX handler to manage most of its AJAX actions, including pro_woocommerce_update_page_option, with the global elementor_ajax action. It is located in the “elementor/core/common/modules/ajax/module.php” script of the free version (which is required to run Elementor Pro) :

/** * Handle ajax request. * * Verify ajax nonce, and run all the registered actions for this request. * * Fired by `wp_ajax_elementor_ajax` action. * * @since 2.0.0 * @access public */
public function handle_ajax_request() { if ( ! $this->verify_request_nonce() ) { $this->add_response_data( false, esc_html__( 'Token Expired.', 'elementor' ) ) ->send_error( Exceptions::UNAUTHORIZED ); } ...

Anyone using Elementor Pro should ensure they’re running 3.11.7 or later, as all previous versions are vulnerable. It’s also a good idea for these users to check their sites for the signs of infection listed in the PatchStack post.

https://arstechnica.com/?p=1928488




Severe Azure Vulnerability Led to Unauthenticated Remote Code Execution

A high-severity vulnerability in Microsoft’s Azure Service Fabric Explorer could have allowed a remote, unauthenticated attacker to execute arbitrary code, cloud security firm Orca says.

Tracked as CVE-2023-23383 (CVSS score of 8.2), the bug is described as a cross-site scripting (XSS) issue that could lead to the execution of code on containers hosted on a Service Fabric node.

Referred to as ‘Super FabriXss’, the flaw resided in a ‘Node Name’ parameter, which allowed an attacker to embed an iframe to retrieve files from a remote server controlled by the attacker.

By exploiting the security defect, an attacker could execute a malicious PowerShell reverse shell, allowing them to run code on the container deployed to the cluster, potentially leading to system takeover. Both Linux and Windows clusters were found vulnerable to the attack.

After creating a new Azure Service Fabric, the researchers observed that modifying a Node name in the user interface is reflected in the Node’s independent dashboard.

The researchers then crafted a URL and enabled the Cluster Event Type under the Events tab, which allowed them to trigger a JavaScript payload, eventually achieving remote code execution (RCE).

Orca Security’s proof-of-concept (PoC) uses a URL with an embedded iframe that triggers an upgrade of an Internet Information Services (IIS) application that includes an instruction to download a .bat file containing an encoded reverse shell.

The attacker can then abuse the reverse shell to gain remote access to the application and use it to launch further attacks, access sensitive information, or potentially take over the cluster node hosting the container.

An attacker could create a custom URL that, when accessed by an authenticated user with appropriate permissions, could instruct the user to enable the Cluster Event Type, triggering the code execution chain.

“It’s worth noting that this attack takes advantage of the Cluster Type Toggle options under the Events Tab in the Service Fabric platform that allows an attacker to overwrite an existing Compose deployment by triggering an upgrade with a specially crafted URL from XSS vulnerability,” Orca explains.

Microsoft addressed the vulnerability as part of the March 2023 Patch Tuesday security updates, marking it as ‘important’. Due to the complexity of an attack and required user interaction, the tech giant believes that exploitation of this bug is ‘less likely’.

“The vulnerability is in the web client, but the malicious scripts executed in the victim’s browser translate into actions executed in the (remote) cluster. A victim user would have to click the stored XSS payload injected by the attacker to be compromised,” Microsoft notes in its advisory.

Organizations using Azure Service Fabric Explorer version 9.1.1436.9590 or earlier are advised to update to a patched release as soon as possible. No action is required from Microsoft customers with automatic updates enabled.

Related:Microsoft Cloud Vulnerability Led to Bing Search Hijacking, Exposure of Office 365 Data

Related: Microsoft: No-Interaction Outlook Zero Day Exploited Since Last April

Related: Microsoft SmartScreen Zero-Day Exploited to Deliver Magniber Ransomware

https://www.securityweek.com/severe-azure-vulnerability-led-to-unauthenticated-remote-code-execution/




Unpatched Security Flaws Expose Water Pump Controllers to Remote Hacker Attacks

A water pumping system made by ProPump and Controls is affected by several vulnerabilities that could allow hackers to cause significant problems. 

The impacted product is the Osprey Pump Controller made by US-based ProPump and Controls, a company that specializes in pumping systems and automated controls for a wide range of applications, including golf courses and turf irrigation, municipal water and sewer, biogas, agricultural, and industrial.

The vulnerabilities were discovered by Gjoko Krstic, founder and chief information security engineer of Macedonian cybersecurity research firm Zero Science Lab. The security holes were identified during an assessment at a client that involved the analysis of actual devices — rather than just firmware image analysis, as is often the case with industrial control system (ICS) research. 

Krstic attempted to report his findings to the vendor directly, as well as through the US Cybersecurity and Infrastructure Security Agency (CISA) and Carnegie Mellon University’s Vulnerability Information and Coordination Environment (VINCE). However, the vendor has not responded and the vulnerabilities likely remain unpatched.

SecurityWeek reached out to ProPump and Controls for comment 48 hours before this article was published, but the company has not responded. 

CISA published an advisory describing the vulnerabilities found by Krstic in the Osprey Pump Controller on March 23. Ten individual advisories describing each flaw were also published recently on Zero Science Lab’s website. 

The vulnerabilities include remote code execution, cross-site request forgery (CSRF), authentication bypass, cross-site scripting (XSS), command injection, backdoor access, file disclosure, and session hijacking issues. 

Many of these flaws can be exploited without authentication, and Krstic told SecurityWeek that dozens of controllers are exposed on the internet, including in the case of the client whose network was assessed by Zero Science Lab. 

An attacker could exploit the vulnerabilities to remotely hack a system and take complete control of the device. This can allow them to cause disruption through a DoS attack or perform various types of nefarious activities, depending on what the targeted controller is used for. 

“An attacker can access the controller, and change pressure, cause havoc, manipulate VFDs [variable frequency drives] or entirely cut down the water supply, depending where the controller is applied,” Krstic explained.

According to CISA, the impacted controller is used worldwide in various industries. The agency has advised ProPump and Controls customers to contact the vendor to obtain information on any patches or mitigations. 

However, the Zero Science Lab advisories reveal that CISA has assigned this incident a priority rating of ‘baseline – negligible’, which indicates that it’s “highly unlikely to affect public health or safety, national security, economic security, foreign relations, civil liberties, or public confidence”.

It’s not uncommon for hackers to target water facilities, including in the United States. CISA and other agencies warned in 2021 that ransomware had hit SCADA systems at three water facilities in the country. The warning came just months after a hacker was caught apparently trying to poison a Florida city’s water supply. 

Related: Hacktivist Attacks Show Ease of Hacking Industrial Control Systems

Related: Water Tank Management System Used Worldwide Has Unpatched Security Hole

Related: Ransomware Group Claims Access to SCADA in Confusing UK Water Company Hack

https://www.securityweek.com/unpatched-security-flaws-expose-water-pump-controllers-to-remote-hacker-attacks/




Microsoft Cloud Vulnerability Led to Bing Search Hijacking, Exposure of Office 365 Data

A misconfiguration in Azure Active Directory (AAD) that exposed applications to unauthorized access could have led to a Bing.com takeover, according to cybersecurity firm Wiz.

Microsoft’s AAD, a cloud-based identity and access management (IAM) service, is typically used as the authentication mechanism for Azure App Services and Azure Functions applications.

The service supports different types of account access, including multi-tenant, where any user belonging to any Azure tenant can issue an OAuth token for them, unless proper restrictions are in place.

For multi-tenant applications, developers are responsible for checking a user’s original tenant and enforcing access policies to prevent unauthorized logins, but Wiz discovered that more than 25% of the multi-tenant apps accessible from the internet lack proper validation.

The issue exists because it is not evident to developers that they are responsible for validating user identity, leading to configuration and validation mistakes. What Wiz discovered, however, was that Microsoft’s own applications fell into the same category.

One of these apps was Bing Trivia, a Microsoft application that provided access to a content management system (CMS) linked to Bing.com, and which allowed Wiz researchers to control results on Microsoft’s search engine. Wiz calls the attack ‘BingBang’.

“A malicious actor landing on the Bing Trivia app page could therefore have tampered with any search term and launched misinformation campaigns, as well as phished and impersonated other websites,” Wiz says.

Digging deeper, the researchers discovered that Bing and Office 365 were connected, and that they could add a cross-site scripting (XSS) payload to Bing.com, which allowed them to compromise the Office 365 token of any user. 

This provided them with access to a user’s Office 365 data, including emails, Teams messages, calendar entries, and SharePoint and OneDrive files.

“A malicious actor with the same access could’ve hijacked the most popular search results with the same payload and leaked the sensitive data of millions of users,” Wiz notes.

Other internal Microsoft applications also impacted by the misconfiguration included Mag News, Centralized Notification Service (CNS) API, Contact Center, PoliCheck, Power Automate Blog, and the file management system COSMOS.

“The issues we identified in this research may affect any organization with Azure Active Directory applications that have been configured as multi-tenant but lack sufficient authorization checks. Based on data from our scans, we assess that exposure is significantly more common across Azure App Service and Azure Functions applications, where validation responsibility is unclear to developers,” Wiz notes.

Administrators are advised to check their application configurations to ensure that multi-tenant access is properly configured, or switch to single-tenant authentication if multi-tenancy is not required. For vulnerable applications, checking logs for past activity is also recommended (AAD logs, however, are insufficient for that).

Microsoft addressed the initial Bing issue on January 31, the same day that Wiz reported it. The tech giant patched the vulnerable applications in late February and issued a $40,000 bug bounty reward this week.

Related:CSRF Vulnerability in Kudu SCM Allowed Code Execution in Azure Services

Related:Most Weaponized Vulnerabilities of 2022 and 5 Key Risks: Report

Related:Despite Warnings, Cloud Misconfiguration Problem Remains Disturbing

https://www.securityweek.com/microsoft-cloud-vulnerability-led-to-bing-search-hijacking-exposure-of-office-365-data/