Microsoft Claims Silent Fix for Azure Backup for AKS Vulnerability
Check Azure Backup for AKS logs for silent patch application and verify no unexpected changes.
Check Azure Backup for AKS logs for silent patch application and verify no unexpected changes.
Summary
Microsoft claims it quietly fixed an Azure Backup for AKS vulnerability after a researcher reported it, but no CVE was issued.
The researcher documented a silent patch that Microsoft says was expected behavior and that no product changes were made. Microsoft disputes the claim, stating the behavior was normal and no update was applied. The incident raises questions about Microsoft’s patching transparency and the handling of reported vulnerabilities.
The lack of a CVE or official acknowledgment means customers cannot easily track the fix. The situation underscores the importance of monitoring Azure Backup logs for unexpected changes. The incident may affect enterprise customers using Azure Kubernetes Service for backup. No immediate remediation steps are provided by Microsoft. The case highlights the need for internal verification of Azure backup integrity.
Key changes
- Microsoft claims no product changes were made to Azure Backup for AKS.
- Researcher documented a silent patch without a CVE.
- Microsoft disputes the claim, stating the behavior was expected.
- No official CVE or patch notes were released.
- The incident raises concerns about patch transparency.
- The silent fix was reportedly applied without customer notification.
- The researcher’s report was published on BleepingComputer.
- Microsoft has not issued a public statement or patch.