Blog | G5 Cyber Security

The road to hell is paved with SAML assertions

A vulnerability in Microsoft Office 365 SAML Service Provider implementation allowed for cross domain authentication bypass affecting all federated domains. An attacker exploiting this vulnerability could gain unrestricted access to a victims Office 365 account, including access to their email, files stored in OneDrive etc. This vulnerability was jointly discovered by Klemen Bratec from ola prihodnosti Maribor, and Ioannis Kakavas from Greek Research and Technology Network. Microsoft fixed the vulnerability within 7 hours of our report and handled the disclosure process admirably.”]

Source: https://bratec.si/security/2016/04/27/road-to-hell-paved-with-saml-assertions.html

Exit mobile version