Code Injection in Azure App Service on Azure Stack Hub - CVE-2023-21777
Published: February 15, 2023
Azure App Service on Azure Stack Hub
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to unspecified error. A local user with access to the targeted worker role and the ability to deploy a malicious application within the worker can access and modify content of a targeted application or workload and interact with other tenant’s applications and content.