A cybersecurity firm, Wiz, discovered a flaw in Microsoft’s Azure CosmosDB that could have allowed a hacker to remotely compromise any of its users. The vulnerability has been patched, but it’s estimated that thousands of customers could have been affected.
Impact on Microsoft Customers
Microsoft uses CosmosDB to power its own services, including Microsoft Teams and Copilot. The company stated that the problem had been “fully addressed” in cooperation with Wiz and that they had found “no evidence of customer impact based on our investigations.” However, the exact number of customers who could have been affected was not disclosed.
Outside researchers said the flaw discovered by Wiz was serious, with one expert stating that CosmosDB “does have some pretty heavy usage and there is frequently sensitive data that ends up in CosmosDB.” Another expert noted that discoveries of this nature happened periodically across cloud services.
Original reporting: Appleton, WI News Feed (HLL/CB) — read the source article.