PT-2021-4858 · Microsoft · Azure Active Directory+3

Karl Fosaaen

·

Published

2021-11-17

·

Updated

2026-02-24

·

CVE-2021-42306

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Azure Active Directory (AAD) (affected versions not specified) Azure Automation (affected versions not specified) Azure Site Recovery (affected versions not specified) Azure Migrate (affected versions not specified)
Description The issue is related to shortcomings in the authentication procedure, which can allow a remote attacker to gain unauthorized access to protected information. Specifically, an information disclosure vulnerability occurs when a user or application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal. This vulnerability enables a user or service in the tenant with application read access to read the private key data that was added to the application.
Recommendations For Azure Active Directory (AAD), to prevent disclosure of any private key values added to the application, ensure that private key data is protected and not uploaded as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal. As a temporary workaround, consider restricting access to the keyCredential property in Azure AD Application and Service Principal APIs until a patch is available. For Azure Automation, Azure Site Recovery, and Azure Migrate, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Authentication

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2021-05586
CVE-2021-42306

Affected Products

Azure Active Directory
Azure Automation
Azure Migrate
Azure Site Recovery