Source |
The Hacker News |
Identifiant |
8623489 |
Date de publication |
2024-12-11 20:02:00 (vue: 2024-12-11 15:08:02) |
Titre |
Microsoft MFA AuthQuake Flaw Enabled Unlimited Brute-Force Attempts Without Alerts |
Texte |
Cybersecurity researchers have flagged a "critical" security vulnerability in Microsoft\'s multi-factor authentication (MFA) implementation that allows an attacker to trivially sidestep the protection and gain unauthorized access to a victim\'s account.
"The bypass was simple: it took around an hour to execute, required no user interaction and did not generate any notification or provide the
Cybersecurity researchers have flagged a "critical" security vulnerability in Microsoft\'s multi-factor authentication (MFA) implementation that allows an attacker to trivially sidestep the protection and gain unauthorized access to a victim\'s account.
"The bypass was simple: it took around an hour to execute, required no user interaction and did not generate any notification or provide the |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
access account alerts allows any around attacker attempts authentication authquake brute bypass critical cybersecurity did enabled execute factor flagged flaw force gain generate have hour implementation interaction mfa microsoft multi not notification protection provide required researchers security sidestep simple: took trivially unauthorized unlimited user victim vulnerability without |
Tags |
Vulnerability
|
Stories |
|
Move |
|