Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API

0
354
Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API


Jan 02, 2025Ravie LakshmananVulnerability / Data Protection

Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API

Details have emerged about three now-patched safety vulnerabilities in Dynamics 365 and Power Apps Web API that would end in knowledge publicity.

The flaws, found by Melbourne-based cybersecurity firm Stratus Security, have been addressed as of May 2024. Two of the three shortcomings reside in Power Platform’s OData Web API Filter, whereas the third vulnerability is rooted within the FetchXML API.

The root reason behind the primary vulnerability is the dearth of entry management on the OData Web API Filter, thereby permitting entry to the contacts desk that holds delicate data resembling full names, cellphone numbers, addresses, monetary knowledge, and password hashes.

Cybersecurity

A risk actor may then weaponize the flaw to carry out a boolean-based search to extract the whole hash by guessing every character of the hash sequentially till the right worth is recognized.

“For instance, we begin by sending startswith(adx_identity_passwordhash, ‘a’) then startswith(adx_identity_passwordhash , ‘aa’) then startswith(adx_identity_passwordhash , ‘ab’) and so forth till it returns outcomes that begin with ab,” Stratus Security mentioned.

“We proceed this course of till the question returns outcomes that begin with ‘ab’. Eventually, when no additional characters return a legitimate outcome, we all know we have now obtained the whole worth.”

Microsoft Dynamics 365 and Power Apps Web API

The second vulnerability, alternatively, lies in utilizing the orderby clause in the identical API to acquire the info from the required database desk column (e.g., EMailAddress1, which refers back to the main e-mail tackle for the contact).

Lastly, Stratus Security additionally discovered that the FetchXML API might be exploited along side the contacts desk to entry restricted columns utilizing an orderby question.

Cybersecurity

“When using the FetchXML API, an attacker can craft an orderby question on any column, utterly bypassing the prevailing entry controls,” it mentioned. “Unlike the earlier vulnerabilities, this technique doesn’t necessitate the orderby to be in descending order, including a layer of flexibility to the assault.”

An attacker weaponizing these flaws may, due to this fact, compile an inventory of password hashes and emails, then crack the passwords or promote the info.

“The discovery of vulnerabilities within the Dynamics 365 and Power Apps API underscores a crucial reminder: cybersecurity requires fixed vigilance, particularly for big corporations that maintain a lot knowledge like Microsoft,” Stratus Security mentioned.

Found this text fascinating? Follow us on Twitter and LinkedIn to learn extra unique content material we put up.



LEAVE A REPLY

Please enter your comment!
Please enter your name here