Azure credentials at risk due to Windows 365 vulnerability

Windows
Windows (Image credit: Microsoft)

What you need to know

  • Windows 365 is Microsoft's new cloud PC service.
  • It contains a big security vulnerability.
  • Using the right program, users can acquire logged-in users' Azure credentials via Windows 365.

No more than a few days ever pass between massive Windows-related PC vulnerability stories. Currently, there's the neverending PrintNightmare saga, as well as a serious vulnerability affecting Windows 365, Microsoft's new cloud PC service. The issue would allow a malicious individual to gain the Azure credentials of individuals logged into Windows 365.

As reported by BleepingComputer, you'd need to have administrative privileges in order to run the specific program capable of exploiting the vulnerability and putting Azure credentials in plaintext. So, for most people, there won't be a major risk, assuming they're not sharing PC admin privileges with anyone they don't trust. However, imagine you're one of the many people who fall victim to phishing schemes, which then results in handing over control of your PC to a cybercriminal. Once they're in there and can remotely run applications and programs on your machine, they can easily utilize the program to sweep up your Azure credentials through Windows 365.

Given that Windows 365 is a business-and-enterprise-focused feature, one can imagine how dangerous credential theft would be if one threat actor infiltrates a W365 machine with corporate info running the backend of things.

As Benjamin Delpy told BleepingComputer, Windows Hello, 2FA, Windows Defender Remote Credential Guard, and other tools would typically be the way to prevent the above issue from existing and threatening users, but said tools aren't in Windows 365 yet, leaving it particularly vulnerable.

Windows 365 is a new service from Microsoft, so there's a chance all the aforementioned security items will be added in time. For now, watch out. As useful as a cloud Windows 11 or Windows 10 PC can be, it's not without risks.

Robert Carnevale

Robert Carnevale is the News Editor for Windows Central. He's a big fan of Kinect (it lives on in his heart), Sonic the Hedgehog, and the legendary intersection of those two titans, Sonic Free Riders. He is the author of Cold War 2395. Have a useful tip? Send it to robert.carnevale@futurenet.com.

Read more
Binary code displayed on a laptop screen and Guy Fawkes mask are seen in this illustration photo.
Microsoft blocks critical Secure Boot loophole after over 7 months — fortifying Windows 11 against sophisticated firmware attacks camouflaged as verified UEFI apps
Windows 365 Link device
Microsoft's Windows 365 Link PC shows up in real life photos ahead of availability this spring
Microsoft CEO Satya Nadella in front of the Microsoft Copilot AI logo.
Windows 11 pirates have a new and unlikely ally — Microsoft Copilot
The Microsoft logo on a smartphone and laptop arranged in Crockett, California, US, on Friday, Dec. 29, 2023.
Massive Microsoft account security change almost snuck out without enough warning
ASUS ExpertBook CX54 Chromebook
Months before millions of PCs will get stuck on Windows 10, Google makes its case for running ChromeOS to use Microsoft 365
Windows App
Say goodbye to Microsoft's Remote Desktop app and get ready to move to the Windows App
Latest in Windows 11
Photo of Microsoft's new sign-in page for Xbox.com using the Microsoft Edge browser.
Over one billion users will get a new Microsoft user experience, and it has a dark mode
Windows 11 answer file
How to easily create an unattended answer file for Windows 11
Windows Update
Microsoft begins testing next phase of Windows 11 — Dev Channel to flight new platform changes
Windows 11 Search
Copilot+ PCs' first must-have feature is just around the corner
Themes section of the Microsoft Store on Windows 11
Two of my least favorite things about the Microsoft Store are about to get fixed
Surface Laptop 7
Amazon warns Surface Laptop 7 shoppers as Mojang unveils massive visual update to Minecraft and Microsoft leaks a potential new feature for the Xbox app on Windows 11
Latest in News
Call of Duty: Black Ops 6 Zombies mode screenshots for Shattered Veil map.
The next Call of Duty Zombies map, "Shattered Veil", is dropping earlier than expected
Helldivers 2
The new Helldivers 2 Illuminate Major Order is so important that we got a new stratagem for it
Hogwarts Legacy troll hero image
Hogwarts Legacy DLC reportedly canceled by WB Games
Tom Clancy's Rainbow Six Siege
Rumored Ubisoft and Tencent agreement comes to fruition with 25% stake and new division for the Assassin's Creed developer
In-game screenshot of the player consuming an enemy in Shadow Labyrinth
This isn't your grandpa's Pac-Man — Bandai Namco's iconic character gets a gritty new action game this Summer
Key art for Dragon Quest 1 and 2 HD-2D remake
Every PC and Xbox game shown off during Nintendo Direct March 2025