#VU46010 Input validation error in Azure Sphere
Published: August 25, 2020
Azure Sphere
Microsoft
Description
The vulnerability allows a local attacker to escalate privileges on the system.
The vulnerability exists due to insufficient validation of user-supplied input in the "uid_map" functionality. A local attacker can ise a specially crafted uid_map file, cause multiple applications to get the same UID assigned and gain elevated privileges on the target system.