ended5월 19일· 1 sources

Microsoft's 'By Design' Vulnerability: When Cloud Vendors Sidestep Security Disclosure

Azure 취약점을 '의도된 설계'라 한 Microsoft, CVE 거부로 클라우드 신뢰 추락

Why it matters

Microsoft's rejection of a critical cross-tenant vulnerability in Azure as 'by design' exposes a dangerous gap in cloud security disclosure practices. Without a CVE identifier, enterprises cannot systematically track and remediate the risk, leaving millions of Azure customers potentially exposed to active exploitation. This precedent-breaking decision undermines the coordinated vulnerability disclosure ecosystem and signals that vendors may selectively reclassify serious flaws rather than patch them—eroding trust in cloud platforms.

1
Sources
+0
24h
Growth
125d
Active
Azure vulnerabilityCVE rejectioncross-tenant accessvulnerability disclosureMSRCcloud isolation

Sources

Related Issues