
CVE-2023-21703 – Azure Data Box Gateway Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2023-21703
14 Feb 2023 — Azure Data Box Gateway Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21703 • CWE-502: Deserialization of Untrusted Data •

CVE-2023-21777 – Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2023-21777
14 Feb 2023 — Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21777 • CWE-269: Improper Privilege Management CWE-284: Improper Access Control •

CVE-2022-37968 – Azure Arc-enabled Kubernetes cluster Connect Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2022-37968
11 Oct 2022 — Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster. Additionally, because Azure Stack Edge allows customers to deploy Kubernetes workloads on their devices via Azure Arc, Azure Stack Edge devices are also vulnerable to this vulnerability. Vulnerabilidad de elevación de privilegios en el... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-37968 •

CVE-2022-29149 – Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2022-29149
15 Jun 2022 — Azure Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios en Azure Open Management Infrastructure (OMI) Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-29149 •

CVE-2021-38649 – Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2021-38649
15 Sep 2021 — Open Management Infrastructure Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios en Open Management Infrastructure. Este CVE ID es diferente de CVE-2021-38645, CVE-2021-38648 Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38649 •

CVE-2021-38648 – Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2021-38648
15 Sep 2021 — Open Management Infrastructure Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios en Open Management Infrastructure. Este ID CVE es único desde CVE-2021-38645, CVE-2021-38649 Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. • https://packetstorm.news/files/id/164925 • CWE-287: Improper Authentication •

CVE-2021-38647 – Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-38647
15 Sep 2021 — Open Management Infrastructure Remote Code Execution Vulnerability Una Vulnerabilidad de Ejecución de Código Remota de Open Management Infrastructure By removing the authentication header, an attacker can issue an HTTP request to the OMI management endpoint that will cause it to execute an operating system command as the root user. This vulnerability was patched in OMI version 1.6.8-1 (released September 8th 2021). Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains... • https://packetstorm.news/files/id/164694 • CWE-287: Improper Authentication •

CVE-2021-38645 – Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2021-38645
15 Sep 2021 — Open Management Infrastructure Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios en Open Management Infrastructure. Este CVE ID es diferente de CVE-2021-38648, CVE-2021-38649 Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38645 •

CVE-2019-1234
https://notcve.org/view.php?id=CVE-2019-1234
12 Nov 2019 — A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'. Se presenta una vulnerabilidad de suplantación de identidad cuando Azure Stack no es capaz de comprobar determinadas peticiones, también se conoce como "Azure Stack Spoofing Vulnerability". • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1234 • CWE-290: Authentication Bypass by Spoofing •

CVE-2019-1372
https://notcve.org/view.php?id=CVE-2019-1372
10 Oct 2019 — An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system thereby escaping the Sandbox.The security update addresses the vulnerability by ensuring that Azure App Service sanitizes user inputs., aka 'Azure App Service Remote Code Execution Vulne... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1372 •