KLA12258
Multiple vulnerabilities in Microsoft Azure

Обновлено: 12/08/2021
Дата обнаружения
10/08/2021
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to bypass security restrictions, obtain sensitive information, gain privileges, cause denial of service.

Below is a complete list of vulnerabilities:

  1. A security bypass Microsoft Azure can be exploited remotely to bypass security restrictions.
  2. An information disclosure vulnerability in Azure Sphere can be exploited remotely to obtain sensitive information.
  3. An elevation of privilege vulnerability in Azure Sphere can be exploited remotely to gain privileges.
  4. An elevation of privilege vulnerability in Azure CycleCloud can be exploited remotely to gain privileges.
  5. A denial of service vulnerability in Azure Sphere can be exploited remotely to cause denial of service.
Пораженные продукты

Microsoft Azure Active Directory Connect 2.0.X.Y
Azure Active Directory Connect Provisioning Agent
Azure Sphere
Azure CycleCloud 8.2.0

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2021-36949
CVE-2021-26428
CVE-2021-26429
CVE-2021-36943
CVE-2021-33762
CVE-2021-26430
Оказываемое влияние
?
OSI 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]
Связанные продукты
Microsoft Active Directory
Microsoft Azure
Узнай статистику распространения уязвимостей в твоем регионе