Back to directory
WRITEUP #334

Arbitrary 1-click Azure tenant takeover via MS application

CloudPrivilege escalationCross-tenant vulnerabilityPhishing
byArnau Ortega
Program
Microsoft (Azure)
Published
Apr 26, 2024
Added to HackDex
May 11, 2024
Read Full Writeuphttps://falconforce.nl/arbitrary-1-click-azure-tenant-takeover-via-ms-application/
RELATED WRITEUPS
Addressed AWS defaults risks: OIDC, Terraform and Anonymous to AdministratorAccess
CloudOIDC
Double Agent: Exploiting Pass-through Authentication Credential Validation in Azure AD
CloudPrivilege escalation
UnOAuthorized: Privilege Elevation Through Microsoft Applications
CloudPrivilege escalation
Escalating Privileges in Google Cloud via Open Groups
CloudPrivilege escalation
ConfusedFunction: A Privilege Escalation Vulnerability Impacting GCP Cloud Functions
CloudPrivilege escalation

Built with ❤️ by Shubham Rawat