KLA48837
Multiple vulnerabilities in Microsoft Azure

Обновлено: 29/09/2023
Дата обнаружения
11/04/2023
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to obtain sensitive information, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. An information disclosure vulnerability in Azure Machine Learning can be exploited remotely to obtain sensitive information.
  2. A security feature bypass vulnerability in Azure Service Connector can be exploited remotely to bypass security restrictions.
Пораженные продукты

Azure Machine Learning
Azure Service Connector

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2023-28312
CVE-2023-28300
Оказываемое влияние
?
OSI 
[?]

SB 
[?]
Связанные продукты
Microsoft Azure
CVE-IDS
CVE-2023-283125.0Warning
CVE-2023-283005.0Warning