Описание
Azure Stack Edge Remote Code Execution Vulnerability
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
FAQ
How could an attacker exploit this vulnerability?
An attacker could send a specially crafted file upload request that includes a manipulated file name or path. Because the application does not properly restrict or validate this input, the attacker could cause the file to be written outside the intended folder, potentially overwriting or creating files in other locations on the system.
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
Уязвимость программно-аппаратной платформы Microsoft Azure Stack Edge, связанная с некорректным внешним управлением именем или путем файла, позволяющая нарушителю выполнить произвольный код
EPSS
9.8 Critical
CVSS3