KLA12286
Mutliple vulnerabilities in Microsoft Azure

Обновлено: 28/09/2023
Дата обнаружения
14/09/2021
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to gain privileges, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. An elevation of privilege vulnerability in Open Management Infrastructure can be exploited remotely to gain privileges.
  2. An information disclosure vulnerability in Microsoft Accessibility Insights for Android can be exploited remotely to obtain sensitive information.
  3. A remote code execution vulnerability in Open Management Infrastructure can be exploited remotely to execute arbitrary code.
  4. An information disclosure vulnerability in Azure Sphere can be exploited remotely to obtain sensitive information.
Эксплуатация

Public exploits exist for this vulnerability.

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Пораженные продукты

Accessibility Insights for Android
Azure Open Management Infrastructure
Azure Sphere

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2021-38645
CVE-2021-38649
CVE-2021-40448
CVE-2021-38647
CVE-2021-38648
CVE-2021-36956
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

PE 
[?]
Связанные продукты
Microsoft Access
Microsoft Azure
CVE-IDS
CVE-2021-386454.6Warning
CVE-2021-386494.6Warning
CVE-2021-404485.0Warning
CVE-2021-386477.5Critical
CVE-2021-386484.6Warning
CVE-2021-369565.0Warning