Microsoft Teams, Office, Azure and several other Microsoft products are at risk of cybersecurity issues after the Indian Computer Emergency Response Team (CERT-In) issued an alarm over multiple vulnerabilities. The government-backed cybersecurity agency has advised users and organisations to take appropriate security measures and ensure that the latest security updates have been installed.
CERT-In, which works for the Ministry of Electronics and Information Technology (MeitY), said the vulnerabilities found on various Microsoft products could allow attackers to perform a number of malicious activities. These include spoofing, privilege escalation, tampering with data and disclosure of sensitive information. The exploitation of certain Microsoft products could also potentially allow attackers to execute malicious code remotely.
The warning is important because the vulnerabilities aren’t limited to one Microsoft application. Instead, they affect a wide range of products and cloud-based services used by individuals, businesses and government organisations. Microsoft Teams, Microsoft Office SharePoint, Azure SQL Managed Instance and Azure SQL Database are among the services covered by the alert.
Other affected services and platforms mentioned in the warning include Azure Active Directory, Microsoft Entra Provisioning Service, Microsoft Purview eDiscovery, Microsoft Power Apps, Azure Logic Apps and Azure Service Bus. CERT-In has also listed Azure Confidential Ledger, Microsoft 365 Admin Center, Azure SRE Agent, Microsoft Application Insights Profiler and Microsoft Planetary Computer Pro.
According to the cybersecurity agency, the vulnerabilities are due to weaknesses in authentication and authorisation controls, access permissions, data handling and privileged functions. Such weaknesses may be more severe in enterprise and cloud environments, where a compromised account or service may provide access to sensitive organisational resources.
CERT-In said that attackers may take advantage of some of these weaknesses by sending specially crafted network requests or taking advantage of flaws in authentication, authorisation and resource handling. If an attack is successful, the consequences could include unauthorised access, privilege escalation, sensitive information disclosure and remote code execution.
Privilege escalation is particularly hazardous because it may allow an attacker with very limited access to gain more permissions. Depending on the system and the privileges obtained, this might provide access to confidential information or allow changes to the settings and resources of the system.
Remote code execution is a bigger cybersecurity concern. If successfully exploited, it is possible for an attacker to execute malicious commands or code on a targeted system without the authorization of the system. For companies that rely heavily on Microsoft's cloud platform, such incidents could affect business data, internal systems and connected services.
The warning also underscores the need to have good security practices even if services are hosted in the cloud. Cloud providers such as Microsoft have a robust security infrastructure, but organisations need to apply available updates, set permissions and monitor their environment for suspicious activity.
Users should make sure that Microsoft software and related services are updated to the latest security patches. Users should not delay security updates, particularly when the updates address vulnerabilities classified as critical.
Organisations should take precautions. IT and security teams must check that applicable patches and updates for affected systems have been installed and that all relevant patches and updates have been issued and applied. They should also review authentication and access controls, check privileged accounts and monitor systems for unusual login attempts or changes and other suspicious activities.
Businesses using Microsoft 365, Azure or other enterprise services should also ensure that security teams are aware of the CERT-In warning and check whether any of their deployed products are included in the affected list. Reviewing logs and security alerts can help organisations identify suspicious activity at an early stage.
The CERT-In warning is another reminder that cyberattacks can hit widely used productivity applications as well as cloud infrastructure. Microsoft Teams and Office are deeply integrated into workplace communication and document management, while Azure supports a large variety of business applications and data services. Vulnerabilities in such platforms can therefore have consequences beyond a single device.
Users shouldn’t panic, but they should act on the warning. Installing security updates, maintaining strong authentication practices, limiting unnecessary privileges and monitoring accounts and systems are among the key measures that can reduce cybersecurity risks.
Timely patch management is very important for organisations. Delaying updates can leave existing security weaknesses exposed now that information about vulnerabilities has become public. Companies need to coordinate with their IT and cybersecurity teams to determine which products are affected and ensure that recommended fixes have been implemented.
Overall, Microsoft users need to be on high alert. With the warning covering Teams, Office, Azure and numerous other Microsoft services, both individuals and organisations should check their systems, apply the relevant security updates and monitor for unusual activity. Taking these steps promptly can help reduce the risk of attackers exploiting vulnerabilities to gain unauthorised access or compromise sensitive information.