Guidance for Azure Active Directory (AD) keyCredential property Information Disclosure in Application and Service Principal APIs

Source: https://msrc-blog.microsoft.com/2021/11/17/guidance-for-azure-active-directory-ad-keycredential-property-information-disclosure-in-application-and-service-principal-apis/ Microsoft recently mitigated an information disclosure issue, CVE-2021-42306, to prevent private key data from being stored by some Azure services in the keyCredentials property of an Azure Active Directory (Azure … Read more

We’re Excited to Announce the Launch of Comms Hub!

Source: https://msrc-blog.microsoft.com/2021/10/25/comms-hub/ We are excited to announce the launch of Comms Hub to the Researcher Portal submission experience! With this launch, security researchers will be able to streamline communication with MSRC case … Read more

New High Impact Scenarios and Awards for the Azure Bounty Program

Source: https://msrc-blog.microsoft.com/2021/10/18/new-high-impact-scenarios-and-awards-for-the-azure-bounty-program/ Microsoft is excited to announce new Azure Bounty Program awards up to $60,000 to encourage and reward vulnerability research focused on the highest potential impact to customer security. These increased … Read more

Congratulations to the Top MSRC 2021 Q3 Security Researchers!

Source: https://msrc-blog.microsoft.com/2021/10/14/congratulations-to-the-top-msrc-2021-q3-security-researchers/ Congratulations to all the researchers recognized in this quarter’s MSRC Researcher Recognition Program leaderboard! Thank you to everyone for your hard work and continued partnership to secure customers. The top … Read more

Additional Guidance Regarding OMI Vulnerabilities within Azure VM Management Extensions

Source: https://msrc-blog.microsoft.com/2021/09/16/additional-guidance-regarding-omi-vulnerabilities-within-azure-vm-management-extensions/ On September 14, 2021, Microsoft released fixes for three Elevation of Privilege (EoP) vulnerabilities and one unauthenticated Remote Code Execution (RCE) vulnerability in the Open Management Infrastructure (OMI) framework:  CVE-2021-38645, CVE-2021-38649, CVE-2021-38648, and CVE-2021-38647, respectively.  Open Management Infrastructure (OMI) … Read more

2021 年 9 月のセキュリティ更新プログラム (月例)

Source: https://msrc-blog.microsoft.com/blog/2021/09/202109-security-updates/ 更新 9 月 17 日: 9 月の月例セキュリティ更新日に公開した Open Management Infrastructure (OMI) の脆弱性 CVE-2021-38645, CVE-2021-38649, CVE-2021-38648, CVE-2021-38647 に関して、追加のガイダン

Coordinated disclosure of vulnerability in Azure Container Instances Service

Source: https://msrc-blog.microsoft.com/2021/09/08/coordinated-disclosure-of-vulnerability-in-azure-container-instances-service/ Microsoft recently mitigated a vulnerability reported by a security researcher in the Azure Container Instances (ACI). Our investigation surfaced no unauthorized access to customer data. Out of an abundance of … Read more

Announcing the Launch of the Azure SSRF Security Research Challenge

Source: https://msrc-blog.microsoft.com/2021/08/19/announcing-the-launch-of-the-azure-ssrf-security-research-challenge/ Microsoft is excited to announce the launch of a new, three-month security research challenge under the Azure Security Lab initiative. The Azure Server-Side Request Forgery (SSRF) Research Challenge invites security … Read more

Point and Print Default Behavior Change

Source: https://msrc-blog.microsoft.com/2021/08/10/point-and-print-default-behavior-change/ Our investigation into several vulnerabilities collectively referred to as “PrintNightmare” has determined that the default behavior of Point and Print does not provide customers with the level of security required … Read more

Congratulations to the MSRC 2021 Most Valuable Security Researchers!

Source: https://msrc-blog.microsoft.com/2021/08/04/congratulations-to-the-msrc-2021-most-valuable-security-researchers/ The MSRC Researcher Recognition Program offers public thanks and acknowledgement to the researchers who help protect customers through discovering and sharing security vulnerabilities under Coordinated Vulnerability Disclosure. Today, we are excited … Read more

Introducing Bounty Awards for Teams Mobile Applications Security Research

Source: https://msrc-blog.microsoft.com/2021/07/19/introducing-bounty-awards-for-teams-mobile-applications-security-research/ We are pleased to announce the addition of Microsoft Teams mobile applications to the Microsoft Applications Bounty Program. Through the expanded program we welcome researchers from across the globe to … Read more

Announcing the Top MSRC 2021 Q2 Security Researchers – Congratulations!

Source: https://msrc-blog.microsoft.com/2021/07/15/announcing-the-top-msrc-2021-q2-security-researchers-congratulations/ We’re excited to announce the top contributing researchers for the 2021 Second Quarter (Q2)! Congratulations to all the researchers recognized in this quarter’s leaderboard and thank you to everyone who … Read more

Announcing the Top MSRC 2021 Q2 Security Researchers – Congratulations!

Source: https://msrc-blog.microsoft.com/blog/2021/07/announcing-the-top-msrc-2021-q2-security-researchers-congratulations/ We’re excited to announce the top contributing researchers for the 2021 Second Quarter (Q2)! Congratulations to all the researchers recognized in this quarter’s leaderboard and thank you to everyone who … Read more