Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1653Azure Active Directory Exposes Internal Information Cloud Information disclosure Azure AD Microsoft (Azure) Counter Threat Unit Research Team Bug Bounty2022-04-052023-06-13
1646MSRC – Joint security research write up – Azure AD Consent bypass disclosure with Kim Jamia – Q1/2022 Authorization flaw Microsoft Joosua Santasalo (@SantasaloJoosua) Bug Bounty2022-04-092023-06-13
809SyncJacking: Hard Matching Vulnerability Enables Azure AD Account Takeover Account takeover Azure AD Cloud Microsoft Tomer Nahum (@TomerNahum1) Bug Bounty2022-11-182023-06-13
663Passwordless Persistence and Privilege Escalation in Azure Privilege escalation Cloud Azure AD Microsoft Andy Robbins (@_wald0) Bug Bounty2022-12-212023-06-13
571Azure Active Directory Flaw Allowed SAML Persistence Azure AD SAML SSO Microsoft (Azure) Secureworks Counter Threat Unit (@Secureworks) Bug Bounty2023-01-182023-06-13
501Azure security — Internal recon leveraging lack of access control Azure AD Cloud Security misconfiguration Privilege escalation Microsoft (Azure) Molx32 Bug Bounty2023-02-022023-06-13
476Azure Ad Kerberos Tickets: Pivoting To The Cloud Active Directory Cloud Lateral movement NA Edwin David Bug Bounty2023-02-092023-06-13
256I’d TAP That Pass Azure AD Cloud OAuth NA Daniel Heinsen (@hotnops) Bug Bounty2023-03-292023-06-13
255BingBang: The AAD misconfiguration that led to Bing.com results manipulation and account takeover explained Account takeover Azure AD Cloud XSS Privilege escalation Microsoft (Bing) Hillai Ben-Sasson (@hillai) Bug Bounty2023-03-292023-06-13
62Tampering with Conditional Access Policies Using Azure AD Graph API Cloud Privilege escalation Microsoft (Azure) Secureworks Counter Threat Unit (@Secureworks) Bug Bounty2023-05-232023-06-13