KLA12140
Multiple vulnerabilities in Microsoft Azure

Updated: 04/22/2021
Detect date
?
04/13/2021
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges.

Below is a complete list of vulnerabilities:

  1. An unsigned code execution vulnerability in Azure Sphere can be exploited remotely to execute arbitrary code.
  2. An elevation of privilege vulnerability in Azure ms-rest-nodeauth Library can be exploited remotely to gain privileges.
Affected products

@azure/ms-rest-nodeauth
Azure Sphere

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2021-28460
CVE-2021-28458

Impacts
?
ACE 
[?]

PE 
[?]
Related products
Microsoft Azure
CVE-IDS
?
Find out the statistics of the vulnerabilities spreading in your region