Lucene search

K
kasperskyKaspersky LabKLA60565
HistorySep 12, 2023 - 12:00 a.m.

KLA60565 Multiple vulnerabilities in Microsoft Azure

2023-09-1200:00:00
Kaspersky Lab
threats.kaspersky.com
19
microsoft azure
arbitrary code execution
privilege escalation
update installation
control panel

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.3 High

AI Score

Confidence

High

0.021 Low

EPSS

Percentile

89.2%

Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft Identity Linux Broker can be exploited remotely to execute arbitrary code.
  2. A remote code execution vulnerability in Azure DevOps Server can be exploited remotely to gain privileges.
  3. An elevation of privilege vulnerability in Azure HDInsight Apache Ambari can be exploited remotely to gain privileges.
  4. An elevation of privilege vulnerability in Microsoft Azure Kubernetes Service can be exploited remotely to gain privileges.
  5. A remote code execution vulnerability in Azure DevOps Server can be exploited remotely to execute arbitrary code.

Original advisories

CVE-2023-36736

CVE-2023-38155

CVE-2023-38156

CVE-2023-29332

CVE-2023-33136

Related products

Microsoft-Azure

CVE list

CVE-2023-38155 critical

CVE-2023-33136 critical

CVE-2023-36736 warning

CVE-2023-38156 high

CVE-2023-29332 critical

KB list

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

Affected Products

  • Microsoft Identity Linux BrokerAzure DevOps Server 2022.0.1Azure HDInsightsAzure Kubernetes Service

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.3 High

AI Score

Confidence

High

0.021 Low

EPSS

Percentile

89.2%