First published: Mon Jul 15 2019(Updated: )
An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for users with contributor role, aka 'Azure Automation Elevation of Privilege Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Azure Automation |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0962 has a severity rating that allows unprivileged users with a contributor role to execute unauthorized actions in Azure Automation.
To mitigate CVE-2019-0962, you should review and adjust permissions for 'RunAs accounts' in your Azure Automation environments.
CVE-2019-0962 affects users with the contributor role in Azure Automation who have access to 'RunAs account' runbooks.
In CVE-2019-0962, a RunAs account allows automated runbooks in Azure Automation to perform actions on behalf of users.
Yes, CVE-2019-0962 can potentially lead to a data breach as it allows unauthorized elevation of privileges within Azure Automation.