Microsoft Azure Flaw Exposed RHEL Virtual Machines to Hacking Risk
In terms of delivering public cloud services, an Azure customer recently taught Microsoft a lesson in running a tight ship.
Ian Duffy, a software engineer at online retailer Zalando, had set out to create a secure, custom Red Hat Enterprise Linux (RHEL) machine image to be deployed on both Amazon Web Services (AWS) and Microsoft Azure. During the process, he discovered a vulnerability that could have provided an attacker root access to virtual machines.
Duffy managed to obtain "administrator level access to all of the Microsoft Azure managed Red Hat Update Infrastructure that supplies all the packages for all Red Hat Enterprise Linux instances booted from the Azure marketplace," he wrote in a blog post detailing the flaw.