Описание
Service Fabric Elevation of Privilege
An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions. An unauthenticated remote user could gain rights to the Service Fabric File Store Service if the node is exposed externally via SMB or SCP standard ports and they are using the impacted configuration.
The update addresses the vulnerability by making ineffective the resources created by the impacted configuration.
FAQ
Is there anything I need to be aware of before I install Service Fabric 7.0 CU4?
Yes. Users are required to be on the latest release (Service Fabric 7.0 CU3) before updating to Service Fabric 7.0 CU4.
Please use the following numbers when you need a specific version number. CU4 version number is subject to change if rollout finds a blocking issue.
- Service Fabric 7.0 CU3: 7.0.466.9590 for Windows, 7.0.465.1 for Linux
- Service Fabric 7.0 CU4: 7.0.470.9590 for Windows, 7.0.469.1 for Linux
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
DOS
EPSS
Связанные уязвимости
An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Service Fabric Elevation of Privilege'.
An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Service Fabric Elevation of Privilege'.
Уязвимость службы хранилища файлов File Store Service приложения Service Fabric, позволяющая нарушителю повысить свои привилегии
EPSS