Input validation error in Azure Sphere - #VU46010

 

Input validation error in Azure Sphere - #VU46010

Published: August 25, 2020


Vulnerability identifier: #VU46010
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to escalate privileges on the system.

The vulnerability exists due to insufficient validation of user-supplied input in the "uid_map" functionality. A local attacker can ise a specially crafted uid_map file, cause multiple applications to get the same UID assigned and gain elevated privileges on the target system.


Affected software

Azure Sphere

Remediation

Install updates from vendor's website.

Azure Sphere - update to 20.08

External References

Related Security Bulletins