Описание
Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
FAQ
How do I protect myself from this vulnerability?
For Azure Local Disconnected Operations (ALDO) customers:
To protect against this vulnerability, customers must update their Azure Local Disconnected Operations (ALDO) environment to the latest available release (version 2604 or later). Updates are not available as standalone patches and must be applied as a full system update through the Azure portal. ALDO is a restricted offering, and updates are only available to approved customers via allow-listing.
Customers should follow Microsoft guidance to obtain access and apply the update, using the following documentation:
How to deploy Disconnected Operations for Azure Local
How to update Disconnected Operations for Azure Local
According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.
What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker could gain elevated privileges beyond those normally available to them, allowing actions such as accessing restricted information or performing operations that are typically limited to more highly privileged users or administrators.
How could an attacker exploit this vulnerability?
The most realistic exploitation scenario involves a malicious or compromised insider with existing access to the customer’s environment.
An attacker could exploit this vulnerability if they:
- Already have access to the internal environment (e.g., an internal user, contractor, or compromised account).
- Possess or can obtain relevant identity information such as tenant identifiers, user identifiers, credentials, or tokens.
- Use this access to interact with and attempt exploitation within the Azure Local Disconnected Operations (ALDO) environment.
Because an insider or compromised internal identity already satisfies many of the environmental and authentication requirements, they may bypass several of the barriers that would otherwise make exploitation more difficult.
In external attacker scenarios, exploitation is significantly more constrained. An attacker would first need to:
- Gain access to the customer’s internal network (which may require physical presence or prior compromise), and
- Obtain valid identity context within the environment.
Additionally, Azure Local Disconnected Operations is designed to operate in a disconnected and isolated configuration, limiting direct external exposure and reducing the likelihood of opportunistic remote exploitation.
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
10 Critical
CVSS3
Связанные уязвимости
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
Уязвимость службы развертывания и управления Azure Resource Manager программной платформы Microsoft Azure и программного средства локальной инфраструктуры Azure Local, связанная с недостатками процедуры аутентификации, позволяющая нарушителю повысить свои привилегии
EPSS
10 Critical
CVSS3