Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

Oracle Cloud Infrastructure Vulnerability Exposed Sensitive Data

Cloud security company Wiz has published information on an Oracle Cloud Infrastructure (OCI) vulnerability allowing attackers to modify users’ storage volumes without authorization.

Cloud security company Wiz has published information on an Oracle Cloud Infrastructure (OCI) vulnerability allowing attackers to modify users’ storage volumes without authorization.

Referred to as #AttachMe and mentioned in Oracle’s July 2022 Critical Patch Update, the vulnerability could have exposed sensitive data to attackers knowing the victim’s Oracle Cloud Identifier (OCID).

“OCI customers could have been targeted by an attacker with knowledge of #AttachMe. Any unattached storage volume, or attached storage volumes allowing multi-attachment, could have been read from or written to as long as an attacker had its Oracle Cloud Identifier (OCID),” Wiz security researcher Elad Gabay explains.

Essentially, because of this vulnerability, cloud isolation in OCI no longer worked, allowing anyone to attach disks to virtual machines in other accounts, without requiring permissions.

An attacker could exploit the security issue by acquiring the OCID of the victim and then initiating a compute instance on a tenant located on the same availability domain as the target volume.

After attaching a volume, the attacker could then target the victim’s volume to gain read/write privileges to it. The target volume needs to be either detached or attached as shareable, the security researcher explains.

In addition to being able to exfiltrate sensitive data or steal credentials for lateral movement, this type of access could allow an attacker to modify block volumes and boot volumes to gain code execution capabilities.

The bug, Gabay explains, resided in the validation of write permissions when attaching a volume, allowing for this attach operation to be performed without any authorization.

Advertisement. Scroll to continue reading.

“In addition, attachment was possible across different tenancies: we managed to attach a volume from one tenancy to a compute instance in another tenancy,” the researcher notes.

Successful exploitation of this bug could have allowed an attacker to query all available volumes, obtain their OCIDs, and then access the information stored on them.

Because OCIDs are not generally considered secrets, meaning that they can be found via online searches, Wiz considers that #AttachMe could have been easily exploited for privilege escalation within the same compartment or tenancy, as well as for cross-tenant access.

Oracle addressed the vulnerability one day after Wiz reported it in June. The tech giant mentioned Gabay’s contribution in its July 2022 Critical Patch Update advisory.

Related: Oracle Releases 349 New Security Patches With July 2022 CPU

Related: Class Action Lawsuit Filed Against Oracle Over Data Collection Practices

Related: Oracle Releases 520 New Security Patches With April 2022 CPU

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

CISO Conversations

SecurityWeek talks to Billy Spears, CISO at Teradata (a multi-cloud analytics provider), and Lea Kissner, CISO at cloud security firm Lacework.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.