Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2020-0902

Опубликовано: 10 мар. 2020
Источник: msrc
EPSS Средний

Описание

Service Fabric Elevation of Privilege

An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions. An unauthenticated remote user could gain rights to the Service Fabric File Store Service if the node is exposed externally via SMB or SCP standard ports and they are using the impacted configuration.

The update addresses the vulnerability by making ineffective the resources created by the impacted configuration.

FAQ

Is there anything I need to be aware of before I install Service Fabric 7.0 CU4?

Yes. Users are required to be on the latest release (Service Fabric 7.0 CU3) before updating to Service Fabric 7.0 CU4.

Please use the following numbers when you need a specific version number. CU4 version number is subject to change if rollout finds a blocking issue.

  • Service Fabric 7.0 CU3: 7.0.466.9590 for Windows, 7.0.465.1 for Linux
  • Service Fabric 7.0 CU4: 7.0.470.9590 for Windows, 7.0.469.1 for Linux

Обновления

ПродуктСтатьяОбновление
Azure Service Fabric

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

N/A

DOS

N/A

EPSS

Процентиль: 95%
0.16044
Средний

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Service Fabric Elevation of Privilege'.

github
больше 3 лет назад

An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Service Fabric Elevation of Privilege'.

CVSS3: 10
fstec
почти 6 лет назад

Уязвимость службы хранилища файлов File Store Service приложения Service Fabric, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 95%
0.16044
Средний