Wiz Research发现了Azure Cosmos DB中的严重安全漏洞CosmosEscape,攻击者可通过Gremlin API中的.NET反射机制绕过沙箱限制,实现任意代码执行并获取Cosmos Master Key,进而完全控制任何数据库账户。1 这一平台级密钥可用于检索所有租户、地域和API类型下任何账户的主密钥,使攻击者能够访问存储所有账户信息的配置存储(Config Store)数据库。1
该漏洞影响范围涉及Microsoft Teams和Entra ID等内部服务的数据库。1 Wiz Research于2025年11月20日报告了这一漏洞,Microsoft随即于11月22日部署了临时修复,并在2026年7月完成了长期修复方案。1 Microsoft已确认未发现未授权访问或客户数据泄露的情况,无需客户采取任何行动。1
Wiz Research has identified a severe security flaw in Azure Cosmos DB called CosmosEscape that could enable attackers to obtain platform-level credentials and assume full control over any database account 1. The vulnerability operates through the Gremlin API, exploiting .NET reflection to bypass sandbox restrictions and execute arbitrary code 1. Once compromised, attackers gain access to the Cosmos Master Key—a platform-level credential capable of retrieving master keys across all tenant accounts, regions, and API types 1.
The vulnerability's reach is particularly concerning because the Cosmos DB configuration store, which maintains records of all account information, is itself a Cosmos DB database accessible via the Master Key 1. This means a successful attack could expose sensitive data across multiple Microsoft internal services, including Microsoft Teams and Entra ID 1. Wiz Research reported the flaw on November 20, 2025, prompting Microsoft to deploy a temporary fix on November 22, 2025, with complete long-term remediation completed by July 2026 1. Microsoft has confirmed that no unauthorized access or customer data breaches were detected as a result of the vulnerability, and no action is required from customers 1.
评论
还没有评论,欢迎留下第一条。