Microsoft was flaming fast in fire-fighting a major Office 365 flaw

Office 365

Microsoft has been commended on the speed with which it managed to patch up a huge security flaw in Office 365.

The major vulnerability was discovered by a pair of security researchers, Ioannis Kakavas and Klemen Bratec, who reported it to Redmond on January 5. Microsoft fixed the problem the very same day, which is indeed impressive, but then a swift response was required given the gravity of the issue – and the organisations which were affected.

Redmond sealed up the vulnerability inside seven hours, and "handled the disclosure process admirably" according to Kakavas.

The hole was in the SAML (Security Assertion Markup Language) authentication system and potentially allowed a malicious party exploiting it to access the victim's Office 365 account and everything tied into it such as emails and OneDrive.

SAML shenanigans

Initially the pair believed that this issue only affected Office 365 accounts using SAML 2.0 for cross domain web single sign-on, which was a very limited number of users, but with further probing the researchers found they could crack into the account of any user that had configured their domains as federated (except those with multi-factor authentication enabled).

And those vulnerable Office 365 accounts included BT, Vodafone, British Airways, Intel, IBM, Cisco and the Daily Mail to name a few.

The researchers have only just been given clearance to publish details of the affair, and the pair received a bug bounty reward which was reportedly close to the maximum Microsoft gives out ($15,000 – which is around £10,300, or AU$19,700).

A recent report from Okta showed that Office 365 was the most-used business web app, followed by Salesforce.com, Box, Google Apps for Work, and Amazon Web Services.

Via: Betanews

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring