Under specific circumstances, sensitive information such as client secrets or certificate details may be exposed in the service logs of these applications,” states the advisory. While the impact depends on how securely service logs are handled, organizations with inadequate log protection practices could face significant security risks if malicious actors obtain these credentials. The advisory notes that “Service logs are intended to be handled securely,” emphasizing that organizations with proper log security measures may not be impacted. Organizations using affected versions of Microsoft Identity Web are strongly encouraged to implement the necessary updates or workarounds to protect their authentication credentials from potential exposure. The vulnerability affects Microsoft.Identity.Web, a widely used NuGet package that simplifies Azure Active Directory authentication for .NET applications. Security experts recommend using certificates from KeyVault or a certificate store, or implementing Federation identity credentials with Managed Identity as more secure alternatives. Under specific conditions, it could potentially expose sensitive client secrets and certificate information in service logs. Invalid or Expired Certificates: Logs of services using invalid or expired Base64 encoded certificates or certificate paths with password credential descriptions. “This vulnerability affects confidential client applications, including daemons, web apps, and web APIs. Credential Descriptions: Logs containing local file paths with passwords, Base64 encoded values, or client secrets. However, the widespread use of Microsoft Identity Web across enterprise applications makes this vulnerability particularly concerning. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Marcel Michau was credited with the discovery, and Jean-Marc Prieur and Jenny Ferris from the Microsoft Identity team handled remediation development.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 10 Apr 2025 10:30:13 +0000