← Back to Tech & Science

Microsoft patches critical Azure Cosmos DB flaw after secret key exposure

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

REDMOND — Microsoft has patched a critical vulnerability in its Azure Cosmos DB service that allowed attackers to bypass security controls and retrieve a platform-wide signing key capable of accessing any database within the system. The cloud infrastructure giant addressed the issue on Wednesday, July 30, following an alert from cybersecurity firm Wiz regarding the severity of the exposure.

The flaw resided in the Gremlin query engine component of Azure Cosmos DB, a globally distributed NoSQL database service widely used by enterprises for real-time applications. Researchers identified that the vulnerability permitted malicious actors to escape the intended sandbox environment where Gremlin queries are executed. By exploiting this gap, an attacker could run arbitrary code and extract a high-level authentication secret.

This platform-wide key served as a master credential, theoretically granting unauthorized access to data across multiple customer databases hosted on the compromised infrastructure. The exposure represented a significant breach of isolation protocols designed to keep tenant data separate within Microsoft's cloud architecture.

Wiz reported that the vulnerability was active until it was remediated by Microsoft engineers earlier in the day. Once patched, the mechanism allowing code execution and secret retrieval was neutralized. Security experts noted that while the window for exploitation existed prior to Wednesday afternoon, there is currently no public indication of widespread data theft or malicious activity leveraging this specific flaw.

Microsoft has not released a detailed technical advisory regarding the number of affected customers or whether any unauthorized access attempts were detected before the patch deployment. The company confirmed only that the vulnerability was resolved and urged users to ensure their systems are updated with the latest security patches immediately.

The incident highlights ongoing challenges in securing complex database engines, particularly those supporting multiple query languages like Gremlin. As cloud services become more integrated into enterprise operations, vulnerabilities allowing sandbox escapes pose a heightened risk by potentially compromising not just individual accounts but entire platform segments.

Questions remain regarding whether any third-party actors successfully exploited the vulnerability during its active period or if the flaw was discovered solely through internal audits and external researcher reporting. Additionally, it is unclear how long the vulnerability existed before detection. Microsoft has stated that further details will be provided as part of a routine security update cycle later this week.

Discussion

0 / 2000