Microsoft Azure AI Health Bot Infected With Critical Vulnerabilities
ID: 11f4207e-5ab4-5dfd-b5df-bcf49689eb54
STIX ID: report--11f4207e-5ab4-5dfd-b5df-bcf49689eb54
Feed Name: Dark Reading
Tenable Research identified multiple privilege-escalation and SSRF vulnerabilities in Microsoft Azure's Health Bot service that could be exploited by configuring malicious data connections to cause redirects to the platform's internal metadata service (IMDS), resulting in leaked access tokens and potential cross-tenant resource management. Microsoft quickly patched the issues; researchers emphasize the risks chatbots introduce for sensitive healthcare data and urge stronger security practices during rapid AI development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
