Azure API Management Flaws Let Attackers Take Full Control APIM Service
ID: c43d8714-32a6-5472-96eb-a0e905fb14c3
STIX ID: report--c43d8714-32a6-5472-96eb-a0e905fb14c3
Feed Name: cybersecurityNews.com
**Executive Summary:** Binary Security discovered critical vulnerabilities in Microsoft Azure API Management (APIM) that allow users with Reader role permissions to leverage legacy Azure Resource Manager (ARM) API endpoints to obtain administrative SSO tokens, granting full Management API privileges and exposing subscription keys, OAuth/integration credentials; researchers provided a PoC video, Microsoft has partially fixed issues but legacy APIs remain enabled by default with planned disablement by June 2024, and recommended mitigations include disabling legacy APIs, restricting network access, and hardening Management API settings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
