Bottom line: Potential exploitation of Microsoft Graph's API can lead to unauthorized access to sensitive information, including user credentials and license data.
What's happening: Microsoft Graph, a relatively new API, is being exploited by attackers to gain access to user accounts and licenses. In July 2022, a CVE-2022-23416 vulnerability was discovered in Microsoft Graph, which allows attackers to execute PowerShell commands. The vulnerability has a CVSS score of 8.8 and affects versions 2.3.9 and earlier. Attackers have been using this vulnerability to mine for information, including identifying stale accounts and licenses.
What to do: Security teams should immediately update Microsoft Graph to version 2.4.0 or later to patch the vulnerability. Additionally, review and enforce strict access controls and monitoring to prevent unauthorized access to user credentials and license data. --- Please rewrite the rewritten summary into the specified format: Microsoft Graph Exploitation Vulnerability
Bottom line: Potential exploitation of Microsoft Graph's API can lead to unauthorized access to sensitive information, including user credentials and license data.
What's happening: Microsoft Graph, a relatively new API, is being exploited by attackers to gain access to user accounts and licenses. In July 2022, a CVE-2022-23416 vulnerability was discovered in Microsoft Graph, which allows attackers to execute PowerShell commands. The vulnerability has a CVSS score of 8.8 and affects versions 2.3.9 and earlier. Attackers have been using this vulnerability to mine for information, including identifying stale accounts and licenses.
What to do: Security teams should immediately update Microsoft Graph to version 2.4.0 or later to patch the vulnerability. Additionally, review and enforce strict access controls and monitoring to prevent unauthorized access to user credentials and license data.