ARCHIVED ADVISORY · JANUARY 27, 2022

A consent prompt can be the attacker’s entry point.

Two historical alerts: Microsoft 365 consent phishing and Apple security updates.

Historical publication

The vulnerabilities and patch versions below describe the January 2022 advisory. They do not establish present-day patch compliance.

Microsoft 365 consent phishing

A malicious application called Upgrade used OAuth request links to obtain access to email, contacts and calendars. Consent supplied a token that could remain useful until expiry or revocation.

Controls discussed in the advisory

  • Restrict user consent for illegitimate applications.
  • Detect and block consent-phishing messages.
  • Identify malicious applications through cloud-app monitoring.

Apple updates

CVE-2022-22587 concerned kernel-level code execution and was reported exploited. CVE-2022-22594 concerned cross-origin exposure of sensitive information.

Product2022 update referenced
macOS Monterey12.2
macOS Big Sur11.6.3
macOS CatalinaSecurity Update 2022-001
Safari15.3

The original advisory also covered eight arbitrary-code-execution vulnerabilities.

YOUR NEXT STEP

Put the insight to work.

Discuss your customers, operating model and evaluation requirements with the CYREBRO team.

Talk to the team