March 6, 2024, 8:52 p.m. | Jimi Sebree

Tenable Research Advisories www.tenable.com

Microsoft Azure Synapse Analytics - Privilege Escalation via Vegas Caching Service

A security issue was discovered within Microsoft’s Azure Synapse that allowed for privilege escalation to root on hosts managed by an internal Microsoft subscription ID. While we do not believe that cross-tenant access was possible via this vector, this issue granted access to potentially sensitive environmental information and allowed for the ability to forge data sent to a variety of monitoring services.

The elevated privilege level granted access to… …

analytics azure azure synapse caching escalation microsoft microsoft azure privilege privilege escalation service synapse vegas

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC