mfa-bypass

1 article
Sort: New Top Best
clear filter
0 6/10

A security researcher discovered a rate-limiting vulnerability in Microsoft's password reset flow that could be exploited via concurrent requests to brute-force 7-digit security codes, bypassing encryption and rate limits to enable account takeover even on accounts with 2FA enabled. Microsoft patched the vulnerability and awarded a $50,000 bounty.

Laxman Muthiyah Microsoft MSRC HackerOne Instagram
thezerohack.com · kh4sh3i/bug-bounty-writeups · 4 hours ago · details