A critical vulnerability allowing remote access to sensitive files, including API keys, has been discovered in Microsoft's new NLWeb protocol. Researchers Aonan Guan and Lei Wang reported the flaw in May, with Microsoft patching it in July but not issuing a CVE. The vulnerability, a classic path traversal flaw, is easily exploited via a malformed URL. While Microsoft claims the impacted code isn't used in their products, NLWeb users need to update their builds to remain secure. The incident highlights concerns about Microsoft's balance between rapid AI feature deployment and robust security practices.
Prepared by Jonathan Pierce and reviewed by editorial team.
Comments