Cyber firm Wiz says flaw could have led to mass exposure of Microsoft cloud customers
MSFT•Wiz finds patched flaw in Azure CosmosDB
WASHINGTON, July 30 (Reuters) - Alphabet-owned cybersecurity company Wiz said on Thursday it had found a sweeping flaw that could have compromised Microsoft and thousands of its cloud customers.
Wiz said in a post on its website that a now-patched vulnerability in a key Microsoft database service, Azure CosmosDB, would have allowed a hacker to remotely compromise any of its users.
In a statement, Microsoft said the problem had been "fully addressed" in cooperation with Wiz and that they had found "no evidence of customer impact based on our investigations."
Microsoft did not say how many customers could have been affected, but CosmosDB is one of the pillars of Microsoft's cloud service offerings and is estimated to have thousands of customers.
It is used by companies to store data that helps services such as chatbots, web applications and online retail recommendation engines. Microsoft also uses CosmosDB to power its own services, including Microsoft Teams and Copilot.




