Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g82q-48mj-vh9h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows an attacker to execute two PowerShell cmdlets in context of a privileged account, and perform privileged actions.To exploit this, an attacker would need to authenticate to the AzureÂ? AD Connect server, aka 'Microsoft Azure AD Connect Elevation of Privilege Vulnerability'.

An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows an attacker to execute two PowerShell cmdlets in context of a privileged account, and perform privileged actions.To exploit this, an attacker would need to authenticate to the AzureÂ? AD Connect server, aka 'Microsoft Azure AD Connect Elevation of Privilege Vulnerability'.

EPSS

Процентиль: 88%
0.04334
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 5.3
nvd
больше 6 лет назад

An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows an attacker to execute two PowerShell cmdlets in context of a privileged account, and perform privileged actions.To exploit this, an attacker would need to authenticate to the Azure AD Connect server, aka 'Microsoft Azure AD Connect Elevation of Privilege Vulnerability'.

msrc
больше 6 лет назад

Microsoft Azure AD Connect Elevation of Privilege Vulnerability

CVSS3: 5.3
fstec
больше 6 лет назад

Уязвимость программного средства облачной платформы Microsoft Azure Active Directory Connect, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 88%
0.04334
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-269