Feb. 15, 2023, 3:01 p.m. | emmaline

Blog - Praetorian www.praetorian.com

Microsoft’s Azure Active Directory B2C service contained a cryptographic flaw which allowed an attacker to craft an OAuth refresh token with the contents for any user account. An attacker could redeem this refresh token for a session token, thereby gaining access to a victim account as if the attacker had logged in through a legitimate […]


The post Technical Advisory – Azure B2C – Crypto Misuse and Account Compromise appeared first on Praetorian.

access account account compromise active directory advisory authorization azure azure active directory b2c cloud security compromise crypto cryptography directory flaw microsoft oauth oauth refresh token refresh token service session technical token victim

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC