As outlined in The Register, a 16-year-old security researcher discovered a significant authentication vulnerability within Microsoft's internal Titan analytics service. This flaw allowed unauthorized access to sensitive data and administrative functions.
The researcher, known as Faav, identified a weakness in Titan's API that bypassed signature verification on login tokens. Exploiting this, Faav, with the aid of an AI tool named Antares, gained administrator privileges. This enabled him to submit unauthorized SQL queries, potentially accessing an estimated 17.3 trillion rows of data stored in analytics databases. The vulnerability stemmed from Titan's failure to validate the signature of JSON Web Tokens, despite checking other token components. While the service is restricted to Microsoft employees, the exploit could have exposed employee records, organizational data, and Bing analytics information.
Microsoft has since secured the API and awarded Faav a $5,000 bug bounty for his findings. The company stated that the researcher's disclosure helped them harden their services and improve customer protection.
Source: The Register
