First published: Tue Oct 10 2023(Updated: )
Azure Identity SDK is vulnerable to remote code execution.
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Azure Identity SDK for .NET | ||
nuget/Azure.Identity | <1.10.2 | 1.10.2 |
Microsoft Azure Identity Sdk | <1.10.2 | |
<1.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-36414.
The title of the vulnerability is Azure Identity SDK Remote Code Execution Vulnerability.
The severity of CVE-2023-36414 is rated as high with a severity value of 8.8.
The Azure Identity SDK for .NET by Microsoft is affected by CVE-2023-36414.
To fix CVE-2023-36414, you should update the Azure Identity SDK for .NET to version 1.10.1 or later.