A security researcher has raised concerns that Microsoft has addressed a critical vulnerability in Azure Backup for AKS without formally recognizing the issue or issuing a Common Vulnerabilities and Exposures (CVE) identifier. The researcher claims to have documented evidence of a fix being applied quietly. However, Microsoft has countered these assertions, stating that the changes made were anticipated and that no modifications to the product were necessary. This situation highlights ongoing tensions between security researchers and large tech companies regarding the disclosure and acknowledgment of vulnerabilities. The lack of a CVE can hinder users' awareness of potential risks, making it crucial for companies to maintain transparency in their security practices. The researcher’s claims and Microsoft’s rebuttal underline the complexities involved in vulnerability reporting and the importance of clear communication in cybersecurity.
Microsoft Dismisses Azure Vulnerability Report, No CVE Assigned
A researcher alleges that Microsoft addressed a significant vulnerability in Azure Backup for AKS without acknowledging it or assigning a CVE.
