CVE-2017-4964: Code Injection
Published Apr 6, 2017
·Updated
Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary code on VMs created by the director, aka a "CPI code injection vulnerability."
Affected Software
1 affected component
Cloudfoundry Bosh Azure Cpi=22
Remediation
Patch Available
Event History
Apr 6, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-4964?
CVE-2017-4964 is considered a critical vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2017-4964?
To mitigate CVE-2017-4964, upgrade to a patched version of Cloud Foundry BOSH Azure CPI.
3
What type of attack does CVE-2017-4964 facilitate?
CVE-2017-4964 facilitates a code injection attack via maliciously crafted stemcells.
4
Which version of BOSH Azure CPI is affected by CVE-2017-4964?
CVE-2017-4964 affects BOSH Azure CPI version 22.
5
Who is impacted by CVE-2017-4964?
Users and organizations utilizing Cloud Foundry BOSH Azure CPI version 22 are impacted by CVE-2017-4964.