Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Attacks - No User Interaction, no Alerts: Azure MFA Cracked in an Hour
Attacks Endpoint Security Latest News News & Analysis Security

No User Interaction, no Alerts: Azure MFA Cracked in an Hour

Adam ParlettBy Adam ParlettDecember 12, 2024Updated:December 12, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Azure MFA
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

If you look inside your cybersecurity Christmas cracker later this month to discover a riddle asking – What takes an hour to execute, requires no user interaction, and doesn’t generate any notifications? You might be spitting your sherry out when you reverse the little strip of paper to learn that the answer is a critical vulnerability identified in Microsoft’s Multi-Factor Authentication (MFA) implementation.

A report released this week from Oasis Security’s research team has detailed the recent discovery, explanation, and remediation of a critical vulnerability in Microsoft’s MFA implementation.

Bypassing MFA

The report details how attackers were able to bypass MFA and gain unauthorized access to users’ accounts by exploiting the lack of rate limiting and an extended timeframe for validating the Time-Based One-Time Password (TOTP) codes generated by Microsoft’s Authenticator app.

The process involves the app generating a six-digit code based on a shared secret and the current time, with a new code created every 30 seconds. Users submit this code after entering their username and password.

The code is then sent via a post here for verification, which results in an acceptance or rejection, with ten consequent fail retries supported for a single session.

Crucially, however, this restriction of ten consequent failed attempts was only applied to the temporary session objective. Factor in delays from different time zones and between the validator and the user, and a more significant time delay and potential attack window is created.

The Oasis research team tested the vulnerability and found that this Microsoft vulnerability displayed a tolerance of around three minutes for a single code, two and a half minutes longer than the guideline timeframe of 30 seconds. During this elongated timeframe, the number of attempts available to attackers was six times higher than it should have been.

Multiple, Simultaneous Attempts

During their research, the Oasis team demonstrated a high rate of attempts to crack a six-digit code with a million combinations by rapidly creating new sessions. This method allowed for multiple simultaneous attempts, and during this time, account owners received no alerts about the numerous failed attempts.

Oasis immediately flagged the issue to Microsoft and worked closely with them to resolve it. This led to the implementation of stricter rate limits that kick in following a number of failed attempts. They have also released a blog post detailing the incident, which provides guidelines for organizations using MFA.

For professionals, the confidential information held in Microsoft accounts increasingly goes beyond Outlook, encompassing OneDrive files, Teams chats, Azure Cloud, and much more. Factor in the staggering statistic that Microsoft has over 400 million paid Office 365 seats; the implications of this vulnerability are significant, with the potential consequences devastating.

A Wake-Up Call

Technology professionals have been reacting to the news, with Jason Soroko, Senior Fellow at Sectigo, branding the findings ‘a wake-up call’ and calling on organizations to review their own MFA systems and assess whether they were fit for purpose.

The incident highlighted significant problems with MFA overall, added Kris Bondi, CEO and Co-Founder of Mimoto. “While MFA is better than the use of credentials alone, it should be considered an organization’s minimum acceptable practice, not a state-of-the-art security measure. Even when MFA is operating as expected, it’s validating an endpoint at a specific point in time, not confirming it’s the correct person.”

Finally, James Scobey, Chief Information Security Officer at Keeper Security, pointed out that this incident serves as a reminder that security isn’t just about deploying MFA – it must also be configured properly. “While MFA is undoubtedly a powerful defense, its effectiveness depends on key settings, such as rate limiting to thwart brute-force attempts and user notifications for failed login attempts. These features are not optional; they are critical for enhancing visibility, allowing users to spot suspicious activity early and respond swiftly.”

Vulnerabilities can, of course, be discovered in even the most secure of systems. However, the lack of alerts to the user notifying them of failed sign-in attempts underlines the need to factor in mail alerts to their authentication systems, with account locks triggered upon a certain number of failed attempts. More broadly, this incident reinforces the importance of continuous monitoring alongside the implementation of MFA.

Adam Parlett
Adam Parlett

Adam Parlett is a cybersecurity marketing professional who has been working as a project manager at Bora for over two years. A Sociology graduate from the University of York, Adam enjoys the challenge of finding new and interesting ways to engage audiences with complex Cybersecurity ideas and products.

  • Adam Parlett
    Apache Tomcat Under Siege 2: Well-Hidden Payload
  • Adam Parlett
    NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard
  • Adam Parlett
    Policy Statement Sheds Light on Upcoming UK Cybersecurity Bill
  • Adam Parlett
    New Lazarus Group Scam Targets Crypto Jobseekers

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet

June 1, 20265 Mins Read

Threat Actors Deploy Tiflux RMM for Persistent Remote Access

May 29, 20263 Mins Read

Cyberattack on West Pharmaceutical halts manufacturing across multiple sites

May 15, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}