CSV Injection in Azure Logs by Dmitriy Beryoza
ID: 1f0560e7-095a-5a04-a816-df78d92480dd
STIX ID: report--1f0560e7-095a-5a04-a816-df78d92480dd
Feed Name: Vectra AI Blog
This blog demonstrates an unauthenticated log-injection combined with CSV-injection in Azure: an attacker injects malicious Excel formulas (via user-agent strings) into SigninLogs, and social-engineers an administrator to export and open the logs as CSV. When opened in vulnerable or misconfigured spreadsheet software (older Excel, DDE enabled, or other apps like LibreOffice that evaluate formulas), these formulas can execute commands, fetch remote resources, or exfiltrate sensitive log contents; Microsoft mitigations prevent DDE by default in updated Excel, but other formula-based exfiltration remains a risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
