Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-35255

Опубликовано: 11 июн. 2024
Источник: msrc
CVSS3: 5.5
EPSS Низкий

Описание

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

FAQ

What privileges could be gained by an attacker who successfully exploited the vulnerability?

An attacker who successfully exploited the vulnerability could elevate privileges and read any file on the file system with SYSTEM access permissions.

According to the CVSS metric, Integrity and Availability impact is None (I:N/A:N). What does that mean for this vulnerability?

An attacker who successfully exploits this vulnerability can only obtain read access to the system files by exploiting this vulnerability. The attacker cannot perform write or delete operations on the files.

Which credential types provided by the Azure Identity client library are affected?

The vulnerability exists in the following credential types:

  • DefaultAzureCredential
  • ManagedIdentityCredential

Which credential types provided by the Microsoft Authentication Libraries are affected?

The vulnerability exists in the following credential types:

**What versions of Microsoft Authentication Libraries (MSAL) are affected by this vulnerability? **

Microsoft Authentication LibraryMinimum Version Number AffectedFixed Version Number
MSAL for .NET4.49.14.61.3
MSAL for Java1.14.4-beta1.15.1
MSAL for Node2.7.02.9.2

Обновления

ПродуктСтатьяОбновление
Azure Identity Library for .NET
Microsoft Authentication Library (MSAL) for .NET
Microsoft Authentication Library (MSAL) for Node.js
Microsoft Authentication Library (MSAL) for Java
Azure Identity Library for Go
Azure Identity Library for C++
Azure Identity Library for Java
Azure Identity Library for JavaScript
Azure Identity Library for Python

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 45%
0.00221
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
больше 1 года назад

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

CVSS3: 5.5
nvd
больше 1 года назад

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

suse-cvrf
11 месяцев назад

Security update for python-azure-identity

suse-cvrf
больше 1 года назад

Security update for python-azure-identity

CVSS3: 5.5
github
больше 1 года назад

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

EPSS

Процентиль: 45%
0.00221
Низкий

5.5 Medium

CVSS3