Vulnerability Management

Teen researcher finds flaw in Microsoft’s Titan analytics service

Magnifying glass red bug bounty, green binary code, identify and submit vulnerability reports

As outlined in The Register, a 16-year-old security researcher discovered a significant authentication vulnerability within Microsoft's internal Titan analytics service. This flaw allowed unauthorized access to sensitive data and administrative functions.

The researcher, known as Faav, identified a weakness in Titan's API that bypassed signature verification on login tokens. Exploiting this, Faav, with the aid of an AI tool named Antares, gained administrator privileges. This enabled him to submit unauthorized SQL queries, potentially accessing an estimated 17.3 trillion rows of data stored in analytics databases. The vulnerability stemmed from Titan's failure to validate the signature of JSON Web Tokens, despite checking other token components. While the service is restricted to Microsoft employees, the exploit could have exposed employee records, organizational data, and Bing analytics information.

Microsoft has since secured the API and awarded Faav a $5,000 bug bounty for his findings. The company stated that the researcher's disclosure helped them harden their services and improve customer protection.

Source: The Register

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds