Insider Access Failure: Former Microsoft Engineer’s Unrevoked Privileges Lead to New Zero‑Day Disclosures
What Happened – A former Microsoft Europe employee, Abdelhamid Naceri, disclosed a new Windows Defender zero‑day (codenamed BigDiskBuster) after his termination. Court documents and internal emails show Microsoft did not revoke his access to internal systems for two months following his departure, allowing him to continue probing and releasing vulnerabilities.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of inadequate off‑boarding and privileged‑account de‑provisioning – a core control‑area that continuous‑monitoring programs are built to protect.
- Highlights the need for auditable evidence that access revocation is performed promptly and verified, supporting a defensible audit trail.
- Shows how insider‑threat scenarios can translate into external zero‑day exploits, impacting both product security and downstream customers.
Who Is Affected – Large‑scale software vendors, cloud service providers, and any organization that manages privileged accounts for former employees or contractors.
Recommended Actions
- Review and automate your off‑boarding workflow to ensure immediate revocation of all privileged credentials.
- Deploy continuous monitoring of privileged‑account activity and generate immutable logs for audit readiness.
- Conduct a post‑mortem of the incident to update policies around employee termination and access reviews.
Technical Notes – The disclosed flaw resides in Windows Defender’s scanning engine; while no CVE number is yet assigned, the vulnerability is a remote‑code‑execution risk that could be weaponized by threat actors. Source: DataBreachToday