CVE-2019-1372
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system thereby escaping the Sandbox.The security update addresses the vulnerability by ensuring that Azure App Service sanitizes user inputs., aka 'Azure App Service Remote Code Execution Vulnerability'.
Se presenta una vulnerabilidad de ejecución de código remota cuando Azure App Service/ Antares en Azure Stack no puede comprobar la longitud de un búfer antes de copiar la memoria en él. Un atacante que explotó con éxito esta vulnerabilidad podría permitir que una función no privilegiada ejecutada por el usuario lleve a cabo código en el contexto de NT AUTHORITY\system escapando así del Sandbox. La actualización de seguridad corrige la vulnerabilidad al garantizar que Azure App Service sanea las entradas de los usuarios, también se conoce como "Azure App Service Remote Code Execution Vulnerability".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-26 CVE Reserved
- 2019-10-10 CVE Published
- 2024-08-04 CVE Updated
- 2025-01-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://research.checkpoint.com/2020/remote-cloud-execution-critical-vulnerabilities-in-azure-cloud-infrastructure-part-ii | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1372 | 2020-08-24 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Azure App Service On Azure Stack Search vendor "Microsoft" for product "Azure App Service On Azure Stack" | < 1.7 Search vendor "Microsoft" for product "Azure App Service On Azure Stack" and version " < 1.7" | - |
Affected
|