CVE-2023-36019 β Critical Christmas Gift from Microsoft Power Platform
CVE-2023-36019 is a critical Power Platform Connector vulnerability with a February 17th deadline, and patching it isn’t automatic for existing connectors.
TL;DR
- CVE-2023-36019 is a spoofing vulnerability in the Microsoft Power Platform Connector, carrying a CVSS score of 9.6, patched as part of the December 2023 Patch Tuesday.
- Attackers can exploit it by crafting a malicious link or file that impersonates a legitimate connector, gaining access to a victim’s data, credentials, or system resources.
- Microsoft’s fix requires OAuth 2.0 custom connectors to use a per-connector redirect URI, new connectors get this by default, but existing ones must be updated manually before February 17th, 2024.
- Security teams need to map every custom connector using OAuth 2.0 with a Global Redirect URI to find what’s actually vulnerable.
- Bottom line: patching the platform isn’t enough, most low-code/no-code security issues live in application and flow logic, which is exactly why enterprises need a dedicated LCNC security solution, not just vendor patches.
What do I need to do? Kanopy Security customers are taking the fast lane to remediation.
If you are a Kanopy Security customer, sit back and relax β our solution lets you know through a new type of Insight which connectors need your attention.
If you are not a Kanopy Security customer, look through the list of custom connectors for those who use OAuth 2.0 authentication and are configured with Global Redirect URI.
Or, contact us at [email protected], and we will help you.cessible inside an organization as well as reports that are published to the web.
CVE-2023-36019 in Detail
An attacker can exploit this vulnerability by crafting a malicious link, file, or application that appears to be a legitimate connector and tricking the victim into interacting with it. This could result in the attacker gaining access to the victimβs data, credentials, or system resources. While the vulnerability is in the web server, malicious scripts execute in the victimβs browser on his/her local machine.
Takeaways
This vulnerability highlights the importance of securing low-code/no-code applications and their components, such as custom connectors and third-party components.
Low-code/no-code apps are designed to enable users with little or no coding experience to create and deploy applications quickly and easily. However, this also means that users may not be aware of the potential security risks.
While it is important to follow the security guidance and recommendations provided by Microsoft and other LCAP vendors, including applying the latest patches and updates as soon as possible β it is not enough.
It is evident from this recent incident that security teams need help in identifying vulnerable components and remediating them. Moreover, most of the security issues stem from application and flow logic and therefore do not fall under the responsibility of the LCAP vendor. It is clearly time for enterprises who (rightfully) chose the path of no-code/low-code development to deploy a dedicated security solution for LCNC AppSec.