Searching
..

Click anywhere to stop

KLA61357
Multiple vulnerabilities in Microsoft Azure

Updated: 10/11/2023
Detect date
?
10/10/2023
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Azure Identity SDK can be exploited remotely to execute arbitrary code.
  2. A remote code execution vulnerability in Azure RTOS GUIX Studio can be exploited remotely to execute arbitrary code.
  3. An elevation of privilege vulnerability in Azure HDInsight Apache Oozie Workflow Scheduler can be exploited remotely to gain privileges.
  4. An elevation of privilege vulnerability in Azure DevOps Server can be exploited remotely to gain privileges.
  5. An elevation of privilege vulnerability in Azure Network Watcher VM Agent can be exploited remotely to gain privileges.
Affected products

Azure RTOS GUIX Studio Installer Application
Azure Identity SDK for Java
Azure Identity SDK for JavaScript
Azure Network Watcher VM Extension
Azure DevOps Server 2022.0.1
Azure Identity SDK for Python
Azure Identity SDK for .NET
Azure HDInsight
Azure RTOS GUIX Studio

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2023-36415
CVE-2023-36418
CVE-2023-36419
CVE-2023-36414
CVE-2023-36561
CVE-2023-36737

Impacts
?
ACE 
[?]

PE 
[?]
Related products
Microsoft Azure
.NET
Find out the statistics of the vulnerabilities spreading in your region