logo

Microsoft Azure AI Health Bot Infected With Critical Vulnerabilities

ID: 11f4207e-5ab4-5dfd-b5df-bcf49689eb54

STIX ID: report--11f4207e-5ab4-5dfd-b5df-bcf49689eb54

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-08-13

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

Tenable Research identified multiple privilege-escalation and SSRF vulnerabilities in Microsoft Azure's Health Bot service that could be exploited by configuring malicious data connections to cause redirects to the platform's internal metadata service (IMDS), resulting in leaked access tokens and potential cross-tenant resource management. Microsoft quickly patched the issues; researchers emphasize the risks chatbots introduce for sensitive healthcare data and urge stronger security practices during rapid AI development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.