KLA12258
Multiple vulnerabilities in Microsoft Azure

Updated: 08/12/2021
Detect date
?
08/10/2021
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to bypass security restrictions, obtain sensitive information, gain privileges, cause denial of service.

Below is a complete list of vulnerabilities:

  1. A security bypass Microsoft Azure can be exploited remotely to bypass security restrictions.
  2. An information disclosure vulnerability in Azure Sphere can be exploited remotely to obtain sensitive information.
  3. An elevation of privilege vulnerability in Azure Sphere can be exploited remotely to gain privileges.
  4. An elevation of privilege vulnerability in Azure CycleCloud can be exploited remotely to gain privileges.
  5. A denial of service vulnerability in Azure Sphere can be exploited remotely to cause denial of service.
Affected products

Microsoft Azure Active Directory Connect 2.0.X.Y
Azure Active Directory Connect Provisioning Agent
Azure Sphere
Azure CycleCloud 8.2.0

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2021-36949
CVE-2021-26428
CVE-2021-26429
CVE-2021-36943
CVE-2021-33762
CVE-2021-26430

Impacts
?
OSI 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]
Related products
Microsoft Active Directory
Microsoft Azure
CVE-IDS
?
CVE-2021-369490.0Unknown
CVE-2021-264280.0Unknown
CVE-2021-264290.0Unknown
CVE-2021-369430.0Unknown
CVE-2021-337620.0Unknown
CVE-2021-264300.0Unknown
Find out the statistics of the vulnerabilities spreading in your region