Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Bitcoin Price Breakdown Looks Real, Why BTC Could Dive Below $35K bitcoin news
  • How Plugin’s Blockchain Technology Helps Industries Adapt To Climate Change bitcoin news
  • ‘Dr. Doom’ Nouriel Roubini to Launch Tokenized Dollar Replacement — With Payment and ESG Features – Bitcoin News bitcoin news
  • Bitcoin Dives To $30K, Why Short-term Recovery Seems Possible bitcoin news
  • SkillzVault and ESE Entertainment Win Gold at Muse Creative Awards 2022 – Press release Bitcoin News bitcoin news
  • Cloudflare Thwarts Record DDoS Attack Peaking at 15 Million Requests Per Second cyber security news
  • ALGO Boosted by FIFA Partnership News, as AVAX and Near Rise Higher – Market Updates Bitcoin News bitcoin news
  • Bitcoin Bears Keep Pushing, Why Upsides Remain Limited bitcoin news

Microsoft Mitigates RCE Vulnerability Affecting Azure Synapse and Data Factory

Posted on May 10, 2022 By root


Azure Synapse and Data Factory

Microsoft on Monday disclosed that it mitigated a security flaw affecting Azure Synapse and Azure Data Factory that, if successfully exploited, could result in remote code execution.

The vulnerability, tracked as CVE-2022-29972, has been codenamed “SynLapse” by researchers from Orca Security, who reported the flaw to Microsoft in January 2022.

“The vulnerability was specific to the third-party Open Database Connectivity (ODBC) driver used to connect to Amazon Redshift in Azure Synapse pipelines and Azure Data Factory Integration Runtime (IR) and did not impact Azure Synapse as a whole,” the company said.

“The vulnerability could have allowed an attacker to perform remote command execution across IR infrastructure not limited to a single tenant.”

In other words, a malicious actor can weaponize the bug to acquire the Azure Data Factory service certificate and access another tenant’s Integration Runtimes to gain access to sensitive information, effectively breaking tenant separation protections.

The tech giant, which resolved the security flaw on April 15, said it found no evidence of misuse or malicious activity associated with the vulnerability in the wild.

That said, the Redmond-based company has shared Microsoft Defender for Endpoint and Microsoft Defender Antivirus detections to protect customers from potential exploitation, adding it’s working to bolster the security of third-party data connectors by working with driver vendors.

The findings come a little over two months after Microsoft remediated an “AutoWarp” flaw impacting its Azure Automation service that could have permitted unauthorized access to other Azure customer accounts and take over control.

Last month, Microsoft also resolved a pair of issues — dubbed “ExtraReplica” — with the Azure Database for PostgreSQL Flexible Server that could result in unapproved cross-account database access in a region.





TheHackersNews/

cyber security news

Post navigation

Previous Post: Dragon War is Bringing the Most Exclusive NFT Collections to Magic Eden
Next Post: As Crypto Competition Intensifies, How Should CoinEx Futures Stand Out?

Related Posts

  • Cybercriminals Using New Malware Loader ‘Bumblebee’ in the Wild cyber security news
  • New Saitama backdoor Targeted Official from Jordan’s Foreign Ministry cyber security news
  • Government Agencies Warned of Increase in Cyberattacks Targeting MSPs cyber security news
  • U.S. Charges Venezuelan Doctor for Using and Selling Thanos Ransomware cyber security news
  • [eBook] Your First 90 Days as MSSP: 10 Steps to Success cyber security news
  • U.S Cybersecurity Agency Lists 2021’s Top 15 Most Exploited Software Vulnerabilities cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Hackers Trick Users with Fake Windows 11 Downloads to Distribute Vidar Malware
  • Cyprus Drafts Crypto Rules, May Introduce Them Before EU Regulations – Regulation Bitcoin News
  • MetaOasis AVAX Hackathon News Report – Press release Bitcoin News
  • Pakistan Can Generate $90 Million Annually if It Introduces a 15% Tax on Crypto Transactions – Emerging Markets Bitcoin News
  • QNAP Urges Users to Update NAS Devices to Prevent Deadbolt Ransomware Attacks

Recent Comments

No comments to show.
  • The Nightly Mint: Daily NFT Recap bitcoin news
  • Bitcoin Bearish Signal: Whales Ramp Up Dumping bitcoin news
  • Battle Borgz Publicly Launches on KICK․IO – Press release Bitcoin News bitcoin news
  • Tron Is Trading Within Its Triangle Pattern; What Awaits The Coin Next? bitcoin news
  • ETH Remains Close to 6-Week Low to Start the Weekend – Market Updates Bitcoin News bitcoin news
  • YOANN․IO Seed Launch on KICK․IO – Press release Bitcoin News bitcoin news
  • Bitcoin Gives Bullish Clues, Will The FED Meeting Get In The Way? bitcoin news
  • Australian Taxation Office to Focus on Capital Gains From Crypto Assets – Taxes Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme