Описание
Azure SDK for Python Remote Code Execution Vulnerability
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
FAQ
How could an attacker exploit this vulnerability?
An attacker could supply a maliciously crafted continuation token that, when processed by the Azure AI Language Conversations Authoring SDK, triggers unsafe deserialization and executes attacker‑controlled code on the system using the SDK.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Azure AI Language Authoring |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
Azure AI Language Authoring Elevation of Privilege Vulnerability can Lead to RCE
Уязвимость сервиса Azure AI Language Authoring, связанная с недостатками механизма десериализации, позволяющая нарушителю выполнить произвольный код
EPSS
9.8 Critical
CVSS3