Windows 365 accounts and passwords can be stolen easily

If the hacker gets into the system, the hacker can query the Windows 365 user account and password in plain text.

A security researcher has found a way to retrieve Microsoft Azure user accounts and passwords in plain text from Microsoft's new Windows 365 Cloud PC service. The tool used to do this is Mimikatz.

Mimikatz is an open source security project created by Benjamin Delpy that allows developers to test a variety of identity theft methods and impersonation vulnerabilities.

Although created for researchers, Mimikatz is also used by hackers to attack users.

Windows 365 is a new service from Microsoft with the ability to provide Cloud PCs over the internet. Customers can rent Cloud PCs in different configurations to work as needed.

Picture 1 of Windows 365 accounts and passwords can be stolen easily

Right after Microsoft offered a trial subscription, developer Benjamin Delpy conducted a number of security tests on Windows 365 Cloud PC. Sharing with BleepingCompute, Delpy said he was able to query Microsoft Azure user accounts and passwords using Mimikatz on Windows 365.

Particularly noteworthy is that the user account and password querying is stored in plain text, unencrypted.

Delpy further shared that he exploited a vulnerability he discovered in May 2021 to be able to query user accounts and passwords. In addition, user accounts and passwords were originally stored encrypted, but Delpy tricked the system into deciphering this information and displaying it to him in plain text.

Is this problem dangerous?

In fact, this type of attack is very difficult to perform. First, the hacker will have to find a way to break into your Windows 365 Cloud PC. They can do this via phishing emails containing malicious code. After the malicious code is activated, the hacker will install a remote access system and then conduct privilege escalation through Windows vulnerabilities.

Finally, hackers use Mimikatz or similar software to query users' accounts and passwords. Once an account has been captured, the hacker will use it to attack both the enterprise's systems and other Microsoft services.

Delpy's discovery is a warning to Microsoft. Windows 365 Cloud PC is a promising service, but it will also face cybersecurity challenges. Hopefully in the future Microsoft will implement more security measures for this service.

Update 15 August 2021
Category

System

Mac OS X

Hardware

Game

Tech info

Technology

Science

Life

Application

Electric

Program

Mobile