#VU46009 Improper access control in Azure Sphere
Published: August 25, 2020
Azure Sphere
Microsoft
Description
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the normal world’s signed code execution functionality. A local attacker can use a specially crafted shellcode that modifies the program at runtime via "/proc/thread-self/mem" and execute arbtrary code on the target system.