Press "Enter" to skip to content

Researchers Disclose Details of Critical ‘CosMiss’ RCE Flaw Affecting Azure Cosmos DB

Researchers Disclose Details of Critical ‘CosMiss’ RCE Flaw Affecting Azure Cosmos DB

Researchers Disclose Details of Critical ‘CosMiss’ RCE Flaw Affecting Azure Cosmos DB

On Tuesday, Microsoft said that it has fixed a security flaw that allowed complete read and write access in Jupyter Notebooks for Azure Cosmos DB.

The tech giant said the problem was introduced on August 12, 2022, and rectified worldwide on October 6, 2022, two days after responsible disclosure from Orca Security, which dubbed the flaw CosMiss.

- CyberInformer_Sticky RightBanner 300x600 high cpm *

ALSO, READ Microsoft Recently Releases Fix for Zero-Day Flaw (July 2022 Edition) Security Patch Rollout

“In short, if an attacker had knowledge of a Notebook’s ‘forwardingId,’ which is the UUID of the Notebook Workspace, they would have had full permissions on the Notebook without having to authenticate, including read and write access, and the ability to modify the file system of the container running the notebook,” researchers Lidor Ben Shitrit and Roee Sagi said.

This container modification could ultimately pave the way for obtaining remote code execution in the Notebook container by overwriting a Python file associated with the Cosmos DB Explorer to spawn a reverse shell.

CyberSecurity

Successful exploitation of the flaw, however, requires that the adversary is in possession of the unique 128-bit forwardingId and that it’s put to use within a one-hour window, after which the temporary Notebook is automatically deleted.

Researchers Disclose Details of Critical ‘CosMiss’ RCE Flaw Affecting Azure Cosmos DB

“The vulnerability, even with knowledge of the forwarding, did not give the ability to execute notebooks, automatically save notebooks in the victim’s (optional) connected GitHub repository, or access to data in the Azure Cosmos DB account,” Redmond said.

ALSO, READ Why All Nigerian Banks Must Have A Cyber Security Department

Microsoft noted in its own advisory that it identified no evidence of malicious activity, adding no action is required from customers. It also described the issue as “difficult to exploit” owing to the randomness of the 128 bit forwadingID and its limited lifespan.

“Customers not using Jupyter Notebooks (99.8% of Azure Cosmos DB customers do NOT use Jupyter notebooks) were not susceptible to this vulnerability,” it further said.


CYBERINFORMER.NET –  brings updates on the latest cyber security tips, online safety tips and cyber information, cyber security courses for Nigerians and Foreigners, Cyber security jobs for seekers and much more…

Be First to Comment

Leave a Reply

Mission News Theme by Compete Themes.
%d bloggers like this: