CVE-2024-27099: Azure IoT Platform Device SDK Double Free Vulnerability
Azure IoT Platform Device SDK Double Free Vulnerability
Other sources
The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect AMQPVALUE failed state, may cause a double free problem. This may cause a RCE. Update submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
uAMQP (AMQP 1.0 C library used by Azure IoT Platform Device SDK)to a version that resolves this vulnerability.Patch 2ca42b6e4e098af2d17e487814a91d05f6ae4987
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27099?
CVE-2024-27099 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-27099?
To remediate CVE-2024-27099, update the uAMQP library to the commit version 2ca42b6e4e098af2d17e487814a91d05f6ae4987.
Which software is affected by CVE-2024-27099?
CVE-2024-27099 affects the Microsoft Azure IoT Platform Device SDK and the uAMQP library.
Can CVE-2024-27099 lead to data breaches?
Yes, CVE-2024-27099 can potentially allow attackers to execute arbitrary code, which may lead to data breaches.
Is CVE-2024-27099 specific to a certain version?
Yes, CVE-2024-27099 specifically affects the uAMQP library at the commit version 2ca42b6e4e098af2d17e487814a91d05f6ae4987.