KLA12286
Mutliple vulnerabilities in Microsoft Azure

Updated: 09/16/2021
Detect date
?
09/14/2021
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to gain privileges, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. An elevation of privilege vulnerability in Open Management Infrastructure can be exploited remotely to gain privileges.
  2. An information disclosure vulnerability in Microsoft Accessibility Insights for Android can be exploited remotely to obtain sensitive information.
  3. A remote code execution vulnerability in Open Management Infrastructure can be exploited remotely to execute arbitrary code.
  4. An information disclosure vulnerability in Azure Sphere can be exploited remotely to obtain sensitive information.
Affected products

Accessibility Insights for Android
Azure Open Management Infrastructure
Azure Sphere

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2021-38645
CVE-2021-38649
CVE-2021-40448
CVE-2021-38647
CVE-2021-38648
CVE-2021-36956

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

PE 
[?]
Related products
Microsoft Access
Microsoft Azure
CVE-IDS
?
CVE-2021-386450.0Unknown
CVE-2021-386490.0Unknown
CVE-2021-404480.0Unknown
CVE-2021-386470.0Unknown
CVE-2021-386480.0Unknown
CVE-2021-369560.0Unknown
Find out the statistics of the vulnerabilities spreading in your region