// For flags

CVE-2019-1372

 

Severity Score

10.0
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system thereby escaping the Sandbox.The security update addresses the vulnerability by ensuring that Azure App Service sanitizes user inputs., aka 'Azure App Service Remote Code Execution Vulnerability'.

Se presenta una vulnerabilidad de ejecución de código remota cuando Azure App Service/ Antares en Azure Stack no puede comprobar la longitud de un búfer antes de copiar la memoria en él. Un atacante que explotó con éxito esta vulnerabilidad podría permitir que una función no privilegiada ejecutada por el usuario lleve a cabo código en el contexto de NT AUTHORITY\system escapando así del Sandbox. La actualización de seguridad corrige la vulnerabilidad al garantizar que Azure App Service sanea las entradas de los usuarios, también se conoce como "Azure App Service Remote Code Execution Vulnerability".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-11-26 CVE Reserved
  • 2019-10-10 CVE Published
  • 2024-08-04 CVE Updated
  • 2025-01-18 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Azure App Service On Azure Stack
Search vendor "Microsoft" for product "Azure App Service On Azure Stack"
< 1.7
Search vendor "Microsoft" for product "Azure App Service On Azure Stack" and version " < 1.7"
-
Affected