logo

Our Experiences Participating in Microsoft’s Azure Sphere Bounty Program

ID: 30b4a087-3bc3-5473-b4cd-de2f010fc66c

STIX ID: report--30b4a087-3bc3-5473-b4cd-de2f010fc66c

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2020-10-06

Date Updated: 2026-04-28

Author: Philippe Laulheret

...
...

McAfee Advanced Threat Research participated in the Microsoft Azure Sphere Research Challenge and identified multiple "important" and "critical" vulnerabilities—including application-package symlink misuse, inclusion of a character device enabling RCE, uid_map processing and azcore handling flaws enabling elevation-of-privilege, and improper certificate management allowing device re-claim—that together allowed a full exploit chain from a locked device to root. The issues were responsibly disclosed to Microsoft, resulted in significant bounty awards (to be donated to charities), and a detailed technical walkthrough was published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.