Wiz Research发现了Azure Cosmos DB中的严重安全漏洞CosmosEscape,攻击者可通过Gremlin API中的.NET反射机制绕过沙箱限制,实现任意代码执行并获取Cosmos Master Key,进而完全控制任何数据库账户。[1] 这一平台级密钥可用于检索所有租户、地域和API类型下任何账户的主密钥,使攻击者能够访问存储所有账户信息的配置存储(Config Store)数据库。[1]
该漏洞影响范围涉及Microsoft Teams和Entra ID等内部服务的数据库。[1] Wiz Research于2025年11月20日报告了这一漏洞,Microsoft随即于11月22日部署了临时修复,并在2026年7月完成了长期修复方案。[1] Microsoft已确认未发现未授权访问或客户数据泄露的情况,无需客户采取任何行动。[1]
Wiz Research has identified a severe security flaw in Azure Cosmos DB called CosmosEscape that could enable attackers to obtain platform-level credentials and assume full control over any database account [1]. The vulnerability operates through the Gremlin API, exploiting .NET reflection to bypass sandbox restrictions and execute arbitrary code [1]. Once compromised, attackers gain access to the Cosmos Master Key—a platform-level credential capable of retrieving master keys across all tenant accounts, regions, and API types [1].
The vulnerability's reach is particularly concerning because the Cosmos DB configuration store, which maintains records of all account information, is itself a Cosmos DB database accessible via the Master Key [1]. This means a successful attack could expose sensitive data across multiple Microsoft internal services, including Microsoft Teams and Entra ID [1]. Wiz Research reported the flaw on November 20, 2025, prompting Microsoft to deploy a temporary fix on November 22, 2025, with complete long-term remediation completed by July 2026 [1]. Microsoft has confirmed that no unauthorized access or customer data breaches were detected as a result of the vulnerability, and no action is required from customers [1].