DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Tenable Research Discovers Critical Vulnerability in Microsoft Copilot Studio

DigitalCIO Bureau by DigitalCIO Bureau
August 21, 2024
in Tech News
0
Tenable Research Discovers Critical Vulnerability in Microsoft Copilot Studio
75
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter
Tenable has disclosed that its Tenable Research Team has discovered a critical information disclosure vulnerability in Microsoft’s Copilot Studio via a server-side request forgery (SSRF), which allowed researchers access to potentially sensitive information regarding service internals with potential cross-tenant impact. This vulnerability exists due to improper handling of redirect status codes for user-configurable actions within Copilot Studio. This follows the team’s recent discoveries of flaws in Microsoft’s Azure Health Bot service, Azure Service Tags and three vulnerabilities in the Azure API Management service. An SSRF vulnerability occurs when an attacker is able to influence the application into making server-side HTTP requests to unexpected targets or in an unexpected way, for example forcing an application on a remote host to make requests to an unintended location. If an attacker is able to control the target of those requests, they could point the request to a sensitive internal resource for which the server-side application has access, even if the attacker doesn’t, revealing potentially sensitive information. Had this issue been exploited by a malicious actor, they would have been able to access the internal infrastructure of Copilot Studio, which is a shared environment among customers. This could have allowed access to Azure’s Instance Metadata Service (IMDS) allowing a threat actor to obtain access tokens for the environment, granting further access to other shared resources, such as a Cosmos DB, where sensitive information regarding the internals of Copilot Studio are stored.
“In the context of cloud applications, a common target is the Instance Metadata Service (IMDS) which, depending on the cloud platform, can yield useful, potentially sensitive information for an attacker. In this case, we were able to retrieve managed identity access tokens from the IMDS. No information beyond the usage of Copilot Studio was required to exploit this flaw,” explains Jimi Sebree, senior staff research engineer, Tenable. “As in some of the previous vulnerabilities found by our research team, this vulnerability demonstrates that mistakes can be made when companies rush to be the first to release products in a new or rapidly expanding space.” Microsoft has confirmed that remediations for this issue were in place as of July 31, 2024. No customer action is required.
Tags: Tenable
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

TrendAI Becomes Part of Anthropic’s Project Glasswing

by DigitalCIO Bureau
June 5, 2026
0
TrendAI Becomes Part of Anthropic’s Project Glasswing

The collaboration will enhance efforts to detect and address software vulnerabilities through advanced AI capabilities. TrendAI, the enterprise AI security leader of Trend Micro, has announced its participation...

Read moreDetails

Tata Technologies Announces Fourth Edition of InnoVent Hackathon with Emerson and AWS, Spotlighting ‘AI at the Edge’

by DigitalCIO Bureau
June 5, 2026
0
Tata Technologies Announces Fourth Edition of InnoVent Hackathon with Emerson and AWS, Spotlighting ‘AI at the Edge’

Tata Technologies announced the launch of the 4th edition of its flagship engineering innovation hackathon, InnoVent-27. Building on its continued success, this year the initiative has been further...

Read moreDetails

Nokian Tyres accelerates its IT transformation through AI-driven modernization, partnering with TCS

by DigitalCIO Bureau
June 4, 2026
0
Nokian Tyres accelerates its IT transformation through AI-driven modernization, partnering with TCS

Combining advanced AI capabilities with deep manufacturing domain expertise, TCS will support Nokian Tyres in driving innovation and sustainable business outcomes Tata Consultancy Services (TCS) has entered into...

Read moreDetails

TCS broadens its collaboration with Euroclear to upgrade Sweden’s central securities depository system

by DigitalCIO Bureau
June 3, 2026
0
TCS broadens its collaboration with Euroclear to upgrade Sweden’s central securities depository system

TCS BaNCS and Quartz will support Euroclear Sweden’s move toward a unified Nordic securities ecosystem across the Finnish and Swedish financial markets. Tata Consultancy Services (TCS) today announced...

Read moreDetails

Hexaware Enables Enterprises to Confidently Scale AI with New Agentverse Enhancements

by DigitalCIO Bureau
June 3, 2026
0
Hexaware Enables Enterprises to Confidently Scale AI with New Agentverse Enhancements

A next-generation platform for building, deploying, and scaling AI across three core layers Hexaware Technologies has introduced new enhancements to Agentverse, its enterprise AI agent platform, focusing on...

Read moreDetails
Next Post

Magic Myna Leverages Dassault Systèmes’ 3DEXPERIENCE Platform For Drone Development

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Athenta’s “EMS” for improved efficiency and decision support

September 3, 2019
Seagate Launches Exos CORVAULT 5U84 Storage Solution at IBC 2023

AVEVA Releases 2024 Sustainability Report

June 26, 2025
CEOs Lack Confidence in Their Organisations’ Ability to Protect Against Cyberattacks: Accenture

Gartner: Security and Risk Management Spending in India to Grow by 12%

February 29, 2024

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Accenture Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation E-books Fortinet Gartner Generative AI Google Cloud IBM India Infographics Infosys Internet of Things (IoT) Kaspersky Microsoft NTT DATA NVIDIA Palo Alto Networks Panel Discussion Salesforce Sophos Strategic Partnership Tata Consultancy Services TCS Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?