Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2023-21777

Опубликовано: 14 фев. 2023
Источник: msrc
CVSS3: 8.7
EPSS Низкий

Описание

Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability

FAQ

According to the CVSS metrics, the attack vector is local (AV:L) and privilege required is low (PR:L). What does that mean for this vulnerability?

An attacker must have access to the targeted worker role and the ability to deploy a malicious application within the worker. The attack itself is carried out locally on the worker role where a malicious application has been deployed.

According to the CVSS metric, successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

This vulnerability could lead to the attacker gaining the ability to interact with other tenant’s applications and content.

According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H) and major loss of integrity (I:H) but have low effect on availability (A:L). What does that mean for this vulnerability?

Exploiting this vulnerability could enable an attacker with the ability to access and modify content of a targeted application or workload leading to major loss of confidentiality and integrity. The attacker cannot fully deny service availability across all infrastructure, hence low effect on availability.

Обновления

ПродуктСтатьяОбновление
Azure App Service on Azure Stack Hub

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 36%
0.00153
Низкий

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.7
nvd
почти 3 года назад

Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability

CVSS3: 8.7
github
почти 3 года назад

Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability

CVSS3: 8.7
fstec
почти 3 года назад

Уязвимость в службе приложений Azure в концентраторе Azure Stack, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 36%
0.00153
Низкий

8.7 High

CVSS3