Feb. 15, 2023, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

Azure Active Directory B2C service (AD B2C) mistakenly implemented RSA encryption using the public part of the key pair instead of the private one.
This cryptographic flaw could have allowed an unauthenticated attacker to craft an OAuth refresh token for any AD B2C user account if they knew their public key.
Moreover, every AD B2C user's public key was recoverable through an unrelated vulnerability (though RSA encryption should not rely on public key secrecy regardless).
An attacker could redeem this …

account account compromise active directory azure azure active directory azure ad b2c compromise directory encryption flaw key oauth oauth refresh token private public public key refresh token rsa rsa encryption service the key token vulnerability

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)