Microsoft Security Breach: 16-Year-Old Exploits JWT Flaw, GameStar Reports
- A 16-year-old security researcher named Faav bypassed token signature verification to access approximately 25,000 internal accounts, 17,990 employee email addresses, and 24,569 dashboards within Microsoft’s Titan internal analytics...
- The vulnerability allowed arbitrary SQL queries to execute with administrator privileges on Azure infrastructure without requiring any sophisticated exploit.
- On August 25, Faav used an artificial intelligence tool named Antares to locate the application programming interface for Titan.
A 16-year-old security researcher named Faav bypassed token signature verification to access approximately 25,000 internal accounts, 17,990 employee email addresses, and 24,569 dashboards within Microsoft’s Titan internal analytics service, GameStar reported.
The vulnerability allowed arbitrary SQL queries to execute with administrator privileges on Azure infrastructure without requiring any sophisticated exploit. Titan checked the content parameters of the token including tenant, target audience, application, and user, but completely ignored its signature, which bypassed all security checks. Paradoxically, the official documentation of the Azure Application Gateway mandates that a token’s signature, issuer, recipient, and validity period must be validated. Microsoft patched the flaw within days of its disclosure and subsequently paid the researcher a 5,000 US-dollar bug bounty.
How the Titan API Exposed 17 Trillion Rows
On August 25, Faav used an artificial intelligence tool named Antares to locate the application programming interface for Titan. While the service’s web frontend was restricted to internal personnel, the underlying API remained exposed on an Azure host without public protection.
Antares tested token variations over a ten-day period before determining that the server accepted authentication tokens completely without a digital signature. To complete the unauthorized access, the system only required a valid username recognized by Titan. The case provides a clear example of AI-supported security research where the artificial intelligence acts as a diligent assistant to human judgment rather than a strategic mastermind; Antares worked repeatedly on the problem for ten days, but the decisive idea of using the username came from the researcher himself.
Faav entered the username admin
into the token field. Titan accepted the input as a local user with administrative rights, executing SQL queries against internal databases without validating the token’s cryptographic integrity, and the researcher also discovered that the service was linked to 17 analytical databases.
Disclosure and Patch Timeline at Microsoft
Faav reported the security flaw to the Microsoft Security Response Center on September 5, the same day the tests concluded. Microsoft closed the vulnerability on September 9 and awarded a 5,000 US-dollar bounty on September 17, as detailed in the researcher’s personal blog.
The security breach relied on a class of vulnerability documented since 2015, when researcher Tim McLean demonstrated that various software libraries accepted authentication tokens without verifying specified algorithms. The Internet Engineering Task Force published official best practices for JSON Web Token handling in 2020.
Microsoft reviewed the research report prior to publication and removed specific sections and figures, while leaving the core technical details intact.
Worth a look
