CosmosEscape: Taking Over Every Database in Azure Cosmos DB
Read original article ↗AI Summary
Wiz Research discovered CosmosEscape, a critical vulnerability in Azure Cosmos DB's Gremlin API that allowed attackers to achieve arbitrary code execution on the database gateway and access the 'Cosmos Master Key'—a platform-wide secret enabling full read and write access to any Cosmos DB account. This vulnerability could have been exploited to enumerate and compromise every database in the service, including Microsoft's internal databases used by services like Microsoft Entra ID, Teams, and Copilot. The attack chain also allowed bypassing network isolation controls, potentially affecting private and network-locked databases. Microsoft has since remediated the issue, deployed mitigations, and rolled out long-term architectural fixes.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.