
A 16-year-old security researcher has disclosed a vulnerability in an internal Microsoft analytics service that could have allowed an attacker to access employee information and Bing search analytics across databases containing an estimated 17.3 trillion rows.
The researcher, known online as Faav, discovered that Microsoft’s Titan service did not properly verify the signatures of login tokens. This could allow an attacker to impersonate an administrator and run SQL queries across 17 connected databases.
Faav used Antares, an automated security research tool he developed, to investigate Titan. According to his account, the tool spent 10 days testing the service’s authentication mechanisms before he identified the final weakness.
“Antares wouldn’t have gotten here alone, and neither would I. Its persistence, plus one human hunch, is what made this find possible.”
Titan’s web interface was accessible only through Microsoft’s VPN, but Faav found a separately documented API endpoint that could process SQL queries. He discovered that changes to token claims were accepted even when the token signature remained unchanged, indicating that the service was not properly validating the signature.
“The payload kept changing while the signature stayed exactly the same, and Titan kept accepting the new claims, like a bouncer checking the name on every ID but never looking at the photo. That was the first big clue it wasn’t verifying signatures,” he wrote.
Faav eventually gained administrator-level access to the service and examined its metadata. The platform database contained approximately 25,000 account and email entries, 17,990 employee email records and 15,001 employee organisation records.
The employee information included job titles, departments and reporting structures for a portion of Microsoft’s workforce. Faav said such information could potentially be useful for targeted social engineering, although he did not test that possibility.
The researcher also accessed a Bing analytics source and retrieved 2 single-row samples from its latest data partition. The samples contained search, identifier and location-related fields. Faav noted that some identifiers appeared across multiple datasets, potentially allowing activity to be correlated between services.
He described the 17.3 trillion-row figure as an estimate based on database metadata and said it likely included historical, duplicated and derived information.
Faav reported the vulnerability to Microsoft Security Response Center on September 5. Microsoft asked him to stop testing and provide his IP address to verify that his activity had remained within the scope of his research.
The affected endpoint was secured on September 9, and Microsoft awarded Faav a $5,000 bounty on September 17.
Faav said he did not access customer data or personally identifiable information and did not attempt to identify individuals or create profiles using the Bing samples.
Microsoft said, “We appreciate the opportunity to investigate the findings reported by Faav. Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services. We value and appreciate safe security research under the terms of the Microsoft Bug Bounty Program and look forward to continuing to work with Faav in the future.”
Faav also said Microsoft reviewed his published account before release and requested changes to some sections, figures and descriptions of the potential impact.
Also read: Viksit Workforce for a Viksit Bharat
Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter
About us:
The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.

