First published: Wed Oct 10 2018(Updated: )
A remote code execution vulnerability exists in the way that Azure IoT Hub Device Client SDK using MQTT protocol accesses objects in memory, aka "Azure IoT Device Client SDK Memory Corruption Vulnerability." This affects Hub Device Client SDK, Azure IoT Edge.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Azure IoT Edge | ||
Microsoft Csharp Software Development Kit |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-8531 is considered critical due to its potential for remote code execution.
To fix CVE-2018-8531, you should update the Azure IoT Hub Device Client SDK and Azure IoT Edge to the latest versions provided by Microsoft.
CVE-2018-8531 affects Microsoft Azure IoT Edge and the Microsoft Csharp Software Development Kit for Azure IoT.
Yes, due to the memory corruption vulnerability in CVE-2018-8531, remote code execution is possible.
The attack vector for CVE-2018-8531 involves exploiting the Azure IoT Hub Device Client SDK when using the MQTT protocol.