Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-35608

Опубликовано: 22 дек. 2020
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an executable memory mapping with controllable content. An attacker can execute a shellcode that uses the PACKET_MMAP functionality to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:microsoft:azure_sphere:20.07:*:*:*:*:*:*:*

EPSS

Процентиль: 47%
0.00242
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-74

Связанные уязвимости

github
больше 3 лет назад

A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an executable memory mapping with controllable content. An attacker can execute a shellcode that uses the PACKET_MMAP functionality to trigger this vulnerability.

EPSS

Процентиль: 47%
0.00242
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-74