Starknex reported a widespread default-configuration exposure in Microsoft Dataverse and Microsoft Power Pages that could allow unauthenticated or guest users to read sensitive records, including Microsoft Entra ID user data, PII, documents, tickets, and portal credentials. The advisory also linked the issue to active threat actor activity by Exfilsquad, while detailing remediation steps such as Conditional Access, auditing, Web API shutdown, and table-permission reviews. #MicrosoftDataverse #MicrosoftPowerPages #Exfilsquad #BillGate
Keypoints
- Dataverse Default environments can expose the systemusers table to guest accounts.
- Power Pages Global-scope table permissions can leak entire datasets through Web API or OData.
- Anonymous Users access can make the exposure fully unauthenticated.
- Exfilsquad reportedly used data consistent with Dataverse misconfigurations in public breach claims.
- Recommended fixes include Conditional Access, auditing, disabling unused APIs, and tightening table permissions.
Read More: https://www.starknex.com/news-media/billgate-dataverse-powerpages-exfilsquad-research