1.3K views
2 years ago

Tenable Research Discovers Critical Vulnerability in Microsoft Copilot Studio

Jimi Sebree, senior staff research engineer, Tenable
Jimi Sebree, senior staff research engineer, Tenable

Tenable has disclosed that its Tenable Research Team has discovered a critical information disclosure vulnerability in Microsoft’s Copilot Studio via a server-side request forgery (SSRF), which allowed researchers access to potentially sensitive information regarding service internals with potential cross-tenant impact. This vulnerability exists due to improper handling of redirect status codes for user-configurable actions within Copilot Studio.

An SSRF vulnerability occurs when an attacker is able to influence the application into making server-side HTTP requests to unexpected targets or in an unexpected way, for example forcing an application on a remote host to make requests to an unintended location. If an attacker is able to control the target of those requests, they could point the request to a sensitive internal resource for which the server-side application has access, even if the attacker doesn’t, revealing potentially sensitive information. Had this issue been exploited by a malicious actor, they would have been able to access the internal infrastructure of Copilot Studio, which is a shared environment among customers. This could have allowed access to Azure’s Instance Metadata Service (IMDS) allowing a threat actor to obtain access tokens for the environment, granting further access to other shared resources, such as a Cosmos DB, where sensitive information regarding the internals of Copilot Studio are stored.

“In the context of cloud applications, a common target is the Instance Metadata Service (IMDS) which, depending on the cloud platform, can yield useful, potentially sensitive information for an attacker. In this case, we were able to retrieve managed identity access tokens from the IMDS. No information beyond the usage of Copilot Studio was required to exploit this flaw,” explains Jimi Sebree, senior staff research engineer, Tenable. “As in some of the previous vulnerabilities found by our research team, this vulnerability demonstrates that mistakes can be made when companies rush to be the first to release products in a new or rapidly expanding space.”

 

Leave a Reply

Latest from Blog

(L-R) Ehab Aljabri, Projects Manager, Fujairah Digital Government; Yousuf Alkaabi, Government Communication Manager, Fujairah Digital Government; Dr. Ahmed Hassan Almurshidi, Director of Fujairah Geographic Information System Center, and Sheikh Eng. Mohammed bin Hamad bin Saif Alsharqi, General Director of Fujairah Digital Government, met with Marwan Zeineddine, Managing Director, SAP UAE, and SAP executives at the launch of the SAP YPP initiative.
(L-R) Ehab Aljabri, Projects Manager, Fujairah Digital Government; Yousuf Alkaabi, Government Communication Manager, Fujairah Digital Government; Dr. Ahmed Hassan Almurshidi, Director of Fujairah Geographic Information System Center, and Sheikh Eng. Mohammed bin Hamad bin Saif Alsharqi, General Director of Fujairah Digital Government, met with Marwan Zeineddine, Managing Director, SAP UAE, and SAP executives at the launch of the SAP YPP initiative.

Don't Miss

Eric Doerr, Chief Product Officer, Tenable.

Tenable expands Tenable One platform to unify application security risks

Tenable Holdings has expanded its Tenable One Exposure Management Platform to integrate
Eric Doerr, Chief Product Officer, Tenable.

Tenable joins OpenAI Daybreak Cyber Partner Program

Tenable has joined the OpenAI Daybreak Cyber Partner Program to integrate frontier

Welcome to

By signing or creating an account you agree with our Code of conduct & Privacy policy