Vulnerability Alert - Virtual Machine contains an Entra browser cookie of the user account

Carl Hansen 40 Reputation points
2024-11-26T02:08:44.8433333+00:00

Hi Team,

We received a Defender alert recently telling us that there is a Virtual Machine that contains an Entra browser cookie of a user account, providing lateral movement to a Key Vault. This happened after one of our Admin users logged in to Azure Portal within the VM. I tried to replicated this but we are not getting alerts for my account with identical privileges.

We have upgraded software in the VM and cleared cache and cookies for the affected user, but we still get the alerts. There seems to be no documentation on this issue, or how to remediate. The only recommendations in Defender are to update software in the VM, nothing about how to remove the Entra cookie.

Is anyone able to assist?

alert

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,375 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
229 questions
{count} votes

Accepted answer
  1. Silvia Wibowo 4,261 Reputation points Microsoft Employee
    2024-12-19T00:00:33.27+00:00

    Hi @Carl Hansen and @Mimi La Bella , I understand you're seeking guidance on what to do about Defender warning on OpenSSL and Python, although there is no newer version available or your application requires a specific version of those components.

    Defender lists out any vulnerability by giving "Attention required" label. It allows security administrators to use the information about the vulnerable component to evaluate the effect of any proposed remediation on the whole organization.

    Then your security admin (or you, if that's your responsibility) needs to decide on what to do, there are 2 buttons available on Defender: Request remediation or Exception options.

    Example of a software recommendation for a vulnerable component.

    More info: Vulnerable components

    Please accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer. Here is how.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.