Searching
..

Click anywhere to stop

KLA20234
Multiple vulnerabilities in Microsoft Azure

Updated: 01/25/2024
Detect date
?
02/14/2023
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to obtain sensitive information, gain privileges, execute arbitrary code, spoof user interface.

Below is a complete list of vulnerabilities:

  1. An information disclosure vulnerability in Azure Machine Learning Compute Instance can be exploited remotely to obtain sensitive information.
  2. An elevation of privilege vulnerability in Azure App Service on Azure Stack Hub can be exploited remotely to gain privileges.
  3. A remote code execution vulnerability in Azure Data Box Gateway can be exploited remotely to execute arbitrary code.
  4. A spoofing vulnerability in Azure DevOps Server 2022 can be exploited remotely to spoof user interface.
Affected products

Azure App Service on Azure Stack Hub
Azure Data Box Gateway
Azure Stack Edge
Azure DevOps Server 2022
Azure Machine Learning

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2023-23382
CVE-2023-21777
CVE-2023-21703
CVE-2023-21564

Impacts
?
ACE 
[?]

OSI 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Related products
Microsoft Edge
Microsoft Azure
CVE-IDS
?
Microsoft official advisories
Microsoft Security Update Guide
Find out the statistics of the vulnerabilities spreading in your region