
Critical CSPM Vulnerability Spotted: What You Need to Know
Source: YouTube · SANS Cloud Security · published Nov 6, 2024 · 52:10
BLUF: A critical "confused deputy" vulnerability in Microsoft Defender for Cloud allowed attackers to exfiltrate tenant data by exploiting weak IAM trust validation during cross-tenant scans 0:05.
Key Takeaways:
• The flaw stemmed from insufficient validation of the IAM role session name, allowing an attacker to trick the vendor into scanning a victim's AWS account by reusing the trust relationship after it was severed 1:15.
• Microsoft mitigated the issue by implementing a mandatory check for the role session name, ensuring scans are only accepted if they originate from the specific tenant that established the connection 3:45.
• The discovery highlights broader risks in cloud integrations, emphasizing the need for strict least-privilege IAM policies and the mandatory cleanup of trust relationships when vendors are disconnected 4:10.
This case study underscores the critical importance of validating identity contexts in cloud integrations and the value of responsible disclosure in securing the cloud ecosystem.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
all right welcome everyone really excited to share this vulnerability that my co-author Eric Johnson and I found earlier this year we've been waiting almost a year to be able to share this information with you and I'm really excited to do so in this webcast this is something that we found as a result of working on our course SEC 510 Cloud security controls and mitigations so a lot of the content that you'll be seeing today is covered in the course as well and many other related topics are covered there as well so we're going to first talk about the problem in general and that's why we say that this is a webcast that you need to know something about even if you've never worked with Microsoft Defender for cloud before because we need to understand how we can securely give our cloud data to t…