KLA61357
Multiple vulnerabilities in Microsoft Azure

Обновлено: 11/10/2023
Дата обнаружения
10/10/2023
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Azure Identity SDK can be exploited remotely to execute arbitrary code.
  2. A remote code execution vulnerability in Azure RTOS GUIX Studio can be exploited remotely to execute arbitrary code.
  3. An elevation of privilege vulnerability in Azure HDInsight Apache Oozie Workflow Scheduler can be exploited remotely to gain privileges.
  4. An elevation of privilege vulnerability in Azure DevOps Server can be exploited remotely to gain privileges.
  5. An elevation of privilege vulnerability in Azure Network Watcher VM Agent can be exploited remotely to gain privileges.
Пораженные продукты

Azure RTOS GUIX Studio Installer Application
Azure Identity SDK for Java
Azure Identity SDK for JavaScript
Azure Network Watcher VM Extension
Azure DevOps Server 2022.0.1
Azure Identity SDK for Python
Azure Identity SDK for .NET
Azure HDInsight
Azure RTOS GUIX Studio

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2023-36415
CVE-2023-36418
CVE-2023-36419
CVE-2023-36414
CVE-2023-36561
CVE-2023-36737
Оказываемое влияние
?
ACE 
[?]

PE 
[?]
Связанные продукты
Microsoft Azure
.NET
Узнай статистику распространения уязвимостей в твоем регионе