More Info:

Ensure Azure CName Records are not vulnerable

Risk Level

Medium

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the CName Records vulnerability in Azure, follow these steps using the Azure console:

  1. Sign in to the Azure portal (https://portal.azure.com) using your credentials.

  2. Navigate to the Azure DNS service by searching for “DNS” in the search bar at the top of the portal and selecting “DNS zones” from the results.

  3. Select the DNS zone that contains the vulnerable CName record.

  4. In the DNS zone overview, locate the CName record that needs to be remediated.

  5. Click on the CName record to open its settings.

  6. Review the CName record and ensure it is pointing to a trusted and valid destination.

  7. If the CName record is pointing to an unauthorized or suspicious destination, click on the “Edit” button to modify the record.

  8. In the edit mode, update the CName record to the correct and trusted destination.

  9. Save the changes by clicking on the “Save” button.

  10. After saving the changes, verify that the CName record is now pointing to the intended destination.

  11. Repeat the above steps for any other vulnerable CName records in the DNS zone.

By following these steps, you can remediate the CName Records vulnerability in Azure by ensuring that the CName records are correctly configured and pointing to trusted destinations.