Описание
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
FAQ
According to the CVSS metrics, the attack vector is local (AV:L) and privilege required is low (PR:L). What does that mean for this vulnerability?
An attacker must have access to the targeted worker role and the ability to deploy a malicious application within the worker. The attack itself is carried out locally on the worker role where a malicious application has been deployed.
According to the CVSS metric, successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
This vulnerability could lead to the attacker gaining the ability to interact with other tenant’s applications and content.
According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H) and major loss of integrity (I:H) but have low effect on availability (A:L). What does that mean for this vulnerability?
Exploiting this vulnerability could enable an attacker with the ability to access and modify content of a targeted application or workload leading to major loss of confidentiality and integrity. The attacker cannot fully deny service availability across all infrastructure, hence low effect on availability.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Azure App Service on Azure Stack Hub |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
DOS
EPSS
8.7 High
CVSS3
Связанные уязвимости
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Уязвимость в службе приложений Azure в концентраторе Azure Stack, позволяющая нарушителю повысить свои привилегии
EPSS
8.7 High
CVSS3