cxo voice
  • Business
  • Technology
    • AI
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • Cyber Security
  • View Points
  • Leaders Talk
  • Press Release
    • Submit Press Release
No Result
View All Result
  • Business
  • Technology
    • AI
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • Cyber Security
  • View Points
  • Leaders Talk
  • Press Release
    • Submit Press Release
No Result
View All Result
Leaders Talk and Latest Tech News | CXO VOICE
No Result
View All Result
Home News Cyber Security

Two Security Flaws found in Microsoft Azure, Now Fixed: Check Point

Ranjeet Roy by Ranjeet Roy
January 31, 2020
A A
Microsoft Azure security Flaws by Check Point

Microsoft Azure, the foremost leader in the cloud computing service provider, has been affected by significant security flaws. Check Point researcher identifies two major security flaws on January 30, 2020. Researchers team recognizes that a Microsft Azure network user could have possibly taken control of the complete server, and unlocking a path to business code theft and manipulation.

Nothing to worry, Check Point and Microsoft teams worked together and fixed both the security flaws.

The first security flaw was discovered in Azure Stack; this would have enabled a cybercriminal to capture screenshots and can steal relevant confidential data from the device operating Microsoft Azure.

The second security flaw was found in the Microsoft Azure App service, this flaw would have enabled a cybercriminal to take control of the whole Azure server and consequently gain access over the enterprises’ business code.

How Check Point Identifies Microsoft Azure security flaws 

First, Check Point researchers install Microsoft Azure Stack Development Kit (ASDK) on their server, then they mapped the places they thought they might find vulnerabilities around. Since Azure Stack has similar features to Microsoft Azure’s public cloud, researchers focused on those vectors. 

ADVERTISEMENT

Disclosure

After the identification process, researchers shared its finding with the Microsoft team. Check Point team disclosed the first security flaw on January 19, 2019, in which Microsoft created CVE-2019-1234. The second security flaw was uncovered by Check Point on June 27, 2019, in which Microsoft created CVE-2019-1372. They bothe, Check Point, and Microsoft worked hard to fix these flaws. Full patches for both security flaws in Azure were issued to the public by the end of 2019.


  • Also Read: Enterprise Cybersecurity Threats in 2020

Microsoft Azure Security Flaws

1. Azure Stack security Flaw

Azure Stack, a cloud computing software solution built by Microsoft to empower enterprises to deliver Azure services from their personal owned data center. Microsoft created the Azure Stack as a way to encourage businesses to adopt hybrid cloud computing by providing the power of the cloud while still being able to discuss business and technical effects like regulations, data sovereignty, customization, and latency.

Microsoft Azure security Flaws by Check Point
Azure Stack Overview

Check Point teams got passage to take screenshots and disclose relevant information of Azure tenants and infrastructure devices. This security flaw would allow cybercriminals to get information on any business that has its device running on Azure software. To perform the exploitation, a hacker would first obtain entrance to the Azure Stack Portal, enabling that person to send unauthenticated HTTP requests that provide screenshots and data about tenants and infrastructure devices.

Screenshot capturing and information disclosure

Microsoft Azure security Flaws by Check Point
Screenshot grabbing and information

2. Microsoft Azure App Flaw where Attacker Gets Control of entire Server

Microsoft Azure App Service is a wholly managed “Platform as a Service” (PaaS) that combines Microsoft Azure Websites, Mobile Services, and other services into a single service, adding new capacities that enable integration with on-premises or cloud systems. Microsoft Azure provides users capabilities like as provisioning and deploying web and mobile apps, build engaging iOS, Android, and Windows apps, automating business processes with visual design experience, and integrating with “Software as a Service” (SaaS) applications like Salesforce, Marketo and DropBox.

App
App Service configuration

Azure App users might be aware they can explore home directory by command D:\home, have you tried how it works?, how all tenant app approach own home directory by locating this path? The answer lies in the PreFilterOnCreateCallback function. We discussed before on the SandboxSettings structure, one of its properties is called sandboxRemotePath which contains a UNC file share path to the storage location of the app. DWASSVC sets this path at the start of the IIS worker process by interacting with the driver using the disclosed filter port (FltPort). So when the app tries to access D:\home or other special paths, the filter driver matches and replaces them with the exact ones on the fly. 

Microsoft Azure security Flaws by Check Point

Check Point researchers were able to determine that a cybercriminal could settle tenant applications, data, and accounts by creating a free user in Azure Cloud and running malicious Azure functions. The end result would be that a hacker could potentially take control of the whole Azure server, and consequently take control over all your business code.

  • Also Read: Cost of Data Breach at the End of 2019
Ranjeet Roy

Ranjeet Roy

Professor, Writer, Business Consultant. Ranjeet will love to answer your queries at "[email protected]"

Related Posts

India EU Deal
Business

India, EU Seal ‘Mother of All Deals’ After 20 Years of Talks

January 27, 2026
Zebra Technologies
People

Zebra Technologies Announces Key Leadership Appointments Across Asia Pacific Region

January 27, 2026
US Army and Salesforce
Business

US Army Awards Salesforce $5.6B Contract to Modernize Military Operations

January 27, 2026
HPE and 2degrees Forge Strategic AI Collaboration to Strengthen Data Sovereignty in New Zealand
Business

HPE and 2degrees Forge Strategic AI Collaboration to Strengthen Data Sovereignty in New Zealand

January 27, 2026
Micron Singapore
Business

Micron Launches $24B Singapore Chip Plant to Meet Surging AI Demand

January 27, 2026
Fujitsu
Business

Fujitsu Unveils Next-Generation Enterprise AI Platform enabling autonomous operation of generative AI

January 26, 2026
Amazon Layoffs
Business

Amazon Prepares Second Wave of Corporate Layoffs in Early 2026

January 23, 2026
Kalmar TCS
Press Release

Kalmar Forges Strategic Alliance with TCS To Transform its Enterprise IT Landscape

January 23, 2026
Load More
ADVERTISEMENT

Latest Updates

India EU Deal

India, EU Seal ‘Mother of All Deals’ After 20 Years of Talks

by Deepa Sharma
11 hours ago

Zebra Technologies

Zebra Technologies Announces Key Leadership Appointments Across Asia Pacific Region

by Deepa Sharma
14 hours ago

US Army and Salesforce

US Army Awards Salesforce $5.6B Contract to Modernize Military Operations

by Deepa Sharma
15 hours ago

HPE and 2degrees Forge Strategic AI Collaboration to Strengthen Data Sovereignty in New Zealand

HPE and 2degrees Forge Strategic AI Collaboration to Strengthen Data Sovereignty in New Zealand

by News Desk
16 hours ago

Micron Singapore

Micron Launches $24B Singapore Chip Plant to Meet Surging AI Demand

by Deepa Sharma
16 hours ago

Fujitsu

Fujitsu Unveils Next-Generation Enterprise AI Platform enabling autonomous operation of generative AI

by Deepa Sharma
1 day ago

Expert Views

HDDs storage
Opinion

5 Reasons HDDs Will Continue to Dominate Enterprise Storage in the AI Era

January 13, 2026
Cybersecurity predictions 2026
Opinion

Prioritizing Proactive Cybersecurity as a Strategic Advantage: The Top 5 Predictions for India in 2026

December 23, 2025
Home Routers
Cyber Security

The Home Router Crisis of 2026: How India’s Living Rooms Became the New Cyberwar Frontline

December 23, 2025
Storage Engineers
Opinion

5 Future-Ready Skills Every Storage Engineer Should Build in 2026

December 22, 2025
AI Govern
AI

How CIOs and CISOs Can Govern AI Without Slowing the Business

December 22, 2025

Get Latest Update

Subscribe to our mailing list to receives newsletter direct to your inbox!

ADVERTISEMENT

Leaders Interviews

NewgenONE
Interview

Reimagining Enterprise Transformation: Varun Goswami on the Future of NewgenONE and AI-Driven Automation

-
Jagat Shah, Chairman & CEO of MITSUMI Group
Leaders Talk

Leadership in Emerging Markets: Exclusive Interview with Jagat Shah, Chairman & CEO of MITSUMI Distribution

-
Tokenization
Interview

Revolutionizing Finance: An Exclusive Interview with Sid Ugrankar, Co-founder of Qila.io on the Future of Blockchain and Tokenization

-
Steve Wilson, GenAI Cybersecurity LLMs
Cyber Security

How effective is GenAI in cybersecurity? The role of LLMs and AI in security solutions. [Interview with Steve Wilson]

-

Entrepreneur

Persistent Gender Bias Clouds Perceptions of Leadership in Tech: Study Finds

Top Leadership Skills Entrepreneurs Need in the Age of AI

Samsung Electronics appoints its first female president

Inspiring Women Entrepreneurs in India (2022)

CXOVoice.com is a leading online publication for CXOs, entrepreneurs, senior leaders, developers, and industry professionals. We publish informed analysis, news reporting, expert commentary, and expert insights across enterprise technology, digital transformation, cybersecurity, data, AI, sustainability, and governance.

Connect with us

Easy Links

  • Cryptocurrency
  • Event
  • Blockchain
  • Press Release
  • Resources & Downloads
Loading
  • Home
  • About Us
  • Contact Us
  • Advertise
  • Privacy & Policy
  • Editorial Policy
  • Feedback

Copyright © 2025 de Audience - All Right Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

Our Spring Sale Has Started

You can see how this popup was set up in our step-by-step guide: https://wppopupmaker.com/guides/auto-opening-announcement-popups/

No Result
View All Result
  • Home
  • News
  • Business
  • Technology
  • Cyber Security
  • Opinion
  • Leaders Talk

Copyright © 2025 de Audience - All Right Reserved