high

CredManifest (Azure AD keyCredential property information disclosure)

Published Wed, Nov 17th, 2021
Platforms

Summary

Automation Account 'Run as' credentials (PFX certificates) were being stored in cleartext, in Azure Active Directory (AAD). These credentials were available to anyone with the ability to read information about App Registrations (typically most AAD users).

Affected Services

AAD

Remediation

Regenerate exposed certificate

Tracked CVEs

CVE-2021-42306

References

Disclosure Date
Thu, Oct 7th, 2021
Exploitablity Period
-
Known ITW Exploitation
-
Detection Methods
-
Piercing Index Rating
5.96
(PI:1.5/A3:1.05/A4:1.05/A5:1.05/A6:6/A7:1.1/A8:1.1)
Discovered by
Karl Fosaaen, NetSPI