CyberSecurity SEE

Misconfiguration of Microsoft Power Pages Potentially Exposed 27 Million Records to ExfilSquad

Misconfiguration of Microsoft Power Pages Potentially Exposed 27 Million Records to ExfilSquad

Suspected Misconfiguration of Microsoft Power Pages Leads to Major Data Exposure

In a significant data breach incident, a suspected configuration failure linked to Microsoft Power Pages has been identified as the cause of the exposure of nearly 27 million records across 13 organizations. This breach came to light when ExfilSquad, a notorious data-extortion group, published an immense trove of 382.64 GB of purported victim data via a torrent distribution.

Initial investigations carried out by cybersecurity researchers indicate that the root of the issue does not stem from a zero-day exploit, ransomware deployment, or conventional network intrusion. Rather, it appears to involve publicly readable Microsoft Dataverse tables. This revelation is crucial, as it suggests a misconfiguration problem rather than a vulnerability in the software itself.

Fortra’s Intelligence and Research Experts (FIRE) conducted a thorough assessment of the leaked data and discovered that the datasets shared online closely resemble exports from Microsoft Dynamics 365 Customer Relationship Management (CRM) and Enterprise Resource Planning (ERP) environments supported by Dataverse. Microsoft Power Pages, the platform in question, is designed to assist organizations in creating external-facing web portals that connect to Dataverse. While the platform enables organizations to facilitate various public workflows, such as citizen services, customer support, and application form submissions, access is fundamentally linked to specific table permissions and web-role assignments.

The prevailing hypothesis among researchers is that the affected portals were misconfigured to assign the "Anonymous Users" web role to Dataverse table permissions, leading to public read access. This misconfiguration allowed unauthenticated users to retrieve sensitive records through the exposed API layer of the portal. Importantly, researchers found no evidence suggesting that ExfilSquad required malware, lateral movement, credential theft, or exploited software vulnerabilities to siphon off the data.

This distinction holds operational significance. While a vulnerable application may necessitate patching, a misconfigured portal demands an immediate reassessment of access controls, rigorous data-exposure evaluations, and responses to potential credential or identity risks. This incident highlights an unfortunate yet recurring reality in cloud security: even a legitimate Software as a Service (SaaS) feature, if set up with overly broad anonymous permissions, can evolve into a publicly available data-exfiltration channel.

Organizations relying on such cloud applications should be reminded that a clean endpoint environment does not inherently safeguard their data if a public-facing portal exposes backend tables by design. Fortra’s comprehensive assessment tied the leaked archive to 13 different organizations, equating to an astonishing 27 million records, including sensitive information from various sectors such as government and education. Notable examples of affected entities include the City of Atlanta, the UK Department for Education, and the District of Columbia Public Schools.

As cybersecurity threats evolve, researchers from XM Cyber have recently uncovered a series of new vulnerabilities in Microsoft System Center Configuration Management (SCCM) which could potentially be exploited to enable remote code execution. This underscores the pressing need for organizations to remain vigilant in their cybersecurity practices.

The implications of the exposed data go beyond mere contact information. The leaked datasets reportedly contained personally identifiable information, customer relationship management records, and service and support data. Additionally, in education-related datasets, sensitive information including student names, birth dates, and unique student identifiers were found. This kind of information can fuel spear-phishing campaigns, identity fraud, and account-recovery attacks, posing a significant risk to individuals, employees, students, citizens, and customers.

Emerging in late July, ExfilSquad publicly released this victim data on August 7, effectively transforming extortion claims into a broad downstream risk of privacy invasion and fraud. Once a portal is made public and its API allows for retrieving records, malicious actors can automate the collection process without needing to breach any internal networks.

In light of this incident, security teams managing Microsoft Power Pages are urged to conduct an immediate review of every portal that permits anonymous access to ensure that table permissions grant read rights strictly necessary for business processes. Attention should be directed toward tables that contain sensitive data types, including contacts, accounts, leads, incidents, and custom entities.

Furthermore, administrators should eliminate the Anonymous Users role from any table permission that does not explicitly require public data access. In situations where anonymous access is essential, permissions should be narrowly scoped, limiting the fields exposed by API-enabled tables to only those explicitly required.

To mitigate potential risks, Microsoft has implemented restrictions on anonymous Web API wildcard configurations for specific system tables, designed to reduce unintended data disclosures. Security teams are also encouraged to validate their externally reachable portals, testing these from unauthenticated sessions to confirm that API routes do not return sensitive data.

The incident serves as a crucial reminder that identity and authorization configurations are integral components of an organization’s attack surface. For those deploying Microsoft Power Pages, a single overly permissive web-role assignment can inadvertently transform a customer portal into a massive data-export interface accessible to anyone on the internet. This breach not only highlights the ongoing vulnerabilities associated with cloud data management but also reiterates the importance of stringent security measures to protect sensitive information.

Source link

Exit mobile version