VDB
GCVE-110-NCSC-2024-249
GCVE-110-NCSC-2024-249
Advisory PublishedCVSS 7.5/10
Microsoft heeft kwetsbaarheden verholpen in Azure producten.
Weaknesses (CWE)
CWE-1104Use of Unmaintained Third Party ComponentsCWE-59Improper Link Resolution Before File Access ('Link Following')CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')CWE-200Exposure of Sensitive Information to an Unauthorized Actor
Risk Scores
CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| microsoft | azure_file_sync | — | — |
| microsoft | azure_storage | — | — |
| microsoft | azure_identity_library_for_c__ | — | — |
| microsoft | azure_identity_library_for_java | — | — |
| microsoft | azure_monitor | — | — |
| microsoft | azure_identity_library_for_python | — | — |
| microsoft | azure_data_science_virtual_machines | — | — |
| microsoft | azure_identity_library_for_.net | — | — |
| microsoft | azure_identity_library | — | — |
| microsoft | azure_identity_library_for_javascript | — | — |
| microsoft | microsoft_authentication_library | — | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.