Microsoft's latest security update rollout patched two critical vulnerabilities that could have let attackers take over Microsoft 365 environments without needing valid login details.
- What it is: A critical flaw in the Microsoft 365 Admin Center allowed unauthenticated attackers to gain elevated access, and a separate flaw in SharePoint Online allowed convincing spoofed pages to be served to users.
- Who is affected: Any organisation using Microsoft 365, Exchange Online or SharePoint Online, effectively all Microsoft 365 subscribers.
- What the risk is: Both flaws were rated critical severity, meaning successful exploitation could hand an attacker significant control over a tenant with little effort.
- What to do: Microsoft has already rolled out fixes on the service side, so no separate patching action is required for most cloud-only tenants. If you run Exchange Server on-premises, check your latest cumulative update is installed.
We recommend reviewing your Microsoft 365 admin audit logs for unusual activity over the past month as a precaution. Microsoft also expanded Purview auto-labelling capacity fivefold this month, worth noting if your business relies on it for compliance. Source: Microsoft Security Blog.