Home > Cyber News > Serious ADD Vulnerability that Impacted Bing Results Now Fixed

Serious ADD Vulnerability that Impacted Bing Results Now Fixed

Microsoft addressed a serious vulnerability that impacted the Azure Active Directory (ADD).

The ADD vulnerability impacted several crucial applications and could lead to unauthorized access. One of the exposed applications powers the Bing.com search engine. The vulnerability allowed for modifying search results and XSS attacks against Bing users, according to cloud security firm Wiz.

ADD vulnerability fixed

The attacks could compromise users’ personal data, such as Outlook emails and SharePoint documents. The vulnerabilities, reported to Microsoft in 2022, are now fixed, and Wiz was awarded a bug bounty in the amount of $40,000. Microsoft claims that the vulnerabilities haven’t been exploited in the wild.

ADD Vulnerabilities: Technical Overview

The issues are triggered by the so-called Shared Responsibility Confusion, meaning that Azure applications could be configured incorrectly to enable access from any Microsoft tenant.

“With single-tenant authentication, the impact is limited to the application’s tenant – all users from the same tenant could connect to the application. But with multi-tenant applications, the exposure is as wide as it gets – without proper validation, any Azure user will be able to log in to the application,” Wiz researchers explained.

Threat actors with the same access could have been able to tamper with the most popular search results and leak sensitive data from millions of users. Other vulnerable apps include Mag News, Central Notification Service, Contact Center, PoliCheck, Power Automate Blog, and COSMOS.

Milena Dimitrova

An inspired writer and content manager who has been with SensorsTechForum since the project started. A professional with 10+ years of experience in creating engaging content. Focused on user privacy and malware development, she strongly believes in a world where cybersecurity plays a central role. If common sense makes no sense, she will be there to take notes. Those notes may later turn into articles! Follow Milena @Milenyim

More Posts

Follow Me:

Leave a Comment

Your email address will not be published. Required fields are marked *

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree