Flaw in Microsoft's online services discovered by Avinash

Avinash Sudhodanan in collaboration with Nicolas Dolgin (an intern from SAP, France), recently discovered a serious vulnerability in Microsoft's online services that allows an attacker to make the victim access (without their knowing so) an account controlled by the attacker.

The consequences of the “flaw” discovered by the researchers can be serious. Among these, the attacker can monitor the activity of the victim and the pages they visit, thus acquiring sensitive data. This not only leads to the breach of the victim's privacy, but it may allow the use of the data collected for fraudulent purposes. Also, the attacker can trick the victim by improperly using their credit card or making them pay for services they do not use, such as Skype credit recharging of the attacker's account.

The research was conducted as part of the "Security and Trust of Next Generation Enterprise Information Systems" (SECENTIS) European project.

Microsoft, in its web page “Security Researcher Acknowledgments for Microsoft Online Services” recognizes the security researchers who have helped make Microsoft online services safer. In particular, in the list of security researchers of April 2017 Microsoft acknowledges Avinash and the SECENTIS project.

The all article is available on FKB web site here: A flaw in Microsoft's online services discovered. FBK researcher received recognition for his contribution to Microsoft's online services security.

Tuesday, December 20, 2016 - 09:45