ZDI-CAN-23050: ZDI-24-985: Microsoft Azure Service Fabric servicefabricsdkstorage Uncontrolled Search Path Element Remote Code Execution Vulnerability
Published Jul 29, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Service Fabric for Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.
Affected Software
1 affected component
Microsoft Azure Service Fabric
Event History
Jul 29, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-23050?
The severity of ZDI-CAN-23050 is rated at 9.8 on the CVSS scale.
2
How can I fix ZDI-CAN-23050?
To fix ZDI-CAN-23050, ensure that you apply the latest security patches provided by Microsoft for Azure Service Fabric.
3
Who can exploit ZDI-CAN-23050?
ZDI-CAN-23050 can be exploited by remote attackers without requiring authentication.
4
What does ZDI-CAN-23050 allow attackers to do?
ZDI-CAN-23050 allows remote attackers to execute arbitrary code on affected installations of Service Fabric for Microsoft Azure.
5
Which software is affected by ZDI-CAN-23050?
ZDI-CAN-23050 affects Microsoft Azure Service Fabric installations.