Google-owned cybersecurity firm Wiz has disclosed that it spotted a major vulnerability in Microsoft’s cloud infrastructure that could have allowed hackers to remotely compromise thousands of corporate customers using Azure CosmosDB, one of Microsoft’s flagship database services. Microsoft has fully patched the issue, stating that an internal investigation found no evidence that any customer data was accessed or compromised by malicious actors.
Wiz finds critical vulnerability in a cloud pillar
According to a blog post by Wiz and a report by news agency Reuters, Azure CosmosDB serves as a foundational database for Microsoft’s cloud ecosystem, hosting critical data for online retail recommendation engines, web applications, and chatbots. Microsoft also relies on CosmosDB to power its own flagship products, including Microsoft Teams and Copilot.Wiz said that the now-remediated flaw would have granted an attacker remote access to any organization’s database instance on the service. Ami Luttwak, Chief Technology Officer at Wiz, explained: “When you build in the cloud, and when it’s on Microsoft, it’s usually in CosmosDB.”
Industry experts warn of growing cloud risks
Cybersecurity researchers underscored the severity of the flaw, noting that CosmosDB routinely handles highly sensitive corporate data. Karl Fosaaen, senior vice president at cybersecurity firm NetSpi, described the discovery as significant given CosmosDB’s heavy enterprise usage, though he noted that infrastructure-level discoveries occur periodically across major cloud platforms.Other security leaders warned of the potential fallout had bad actors discovered the loophole first. For example, Vaisha Bernard, co-owner of Eye Security, noted that researchers have increasingly uncovered high-severity vulnerabilities across major infrastructure providers, adding that an exploit prior to Wiz’s discovery “most definitely could have caused some pretty serious damage.”
