AuthQuake vulnerability with Microsoft to Bypass MFA
A view shows a Microsoft logo at Microsoft offices in Issy-les-Moulineaux near Paris, France, January 25, 2023. REUTERS/Gonzalo Fuentes

AuthQuake vulnerability with Microsoft to Bypass MFA


Cybersecurity researchers at Oasis Security have discovered a significant vulnerability in Microsoft’s Multi-Factor Authentication (MFA) system, which they have named AuthQuake.

This vulnerability allows attackers to bypass security measures and gain unauthorized access to user accounts. Given that there are over 400 million paid Office 365 subscriptions, this flaw could be highly lucrative for cybercriminals aiming to steal sensitive information such as emails, files, and communications across Microsoft platforms like Outlook, OneDrive, Teams, and Azure.

The AuthQuake vulnerability exploits two critical issues: a lack of rate limiting and an extended timeframe for validating Time-Based One-Time Password (TOTP) codes. Attackers can rapidly create new sessions and attempt multiple code guesses simultaneously, quickly exhausting all possible 6-digit code combinations. During these attack attempts, account owners receive no alerts about the numerous failed attempts, making this vulnerability particularly stealthy and dangerous.

Oasis Security identified and reported the bug to Microsoft in June 2024. In response, Microsoft acknowledged the issue and implemented a temporary fix in July 2024, followed by a more permanent solution in October 2024, which included stricter rate-limiting mechanisms. Despite the fix, this incident underscores the importance of robust MFA implementations and the ongoing need for organizations to continuously review and update their security configurations.

This vulnerability’s discovery highlights the ever-evolving nature of cyber threats and the importance of maintaining vigilant and proactive security measures. Users and organizations are encouraged to stay informed about potential risks and to promptly apply security updates to protect their data and systems.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.