#VU46011 Improper access control in Azure Sphere
Published: August 25, 2020
Azure Sphere
Microsoft
Description
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the Capability access control functionality. A local attacker can use a set of specially crafted ptrace syscalls, bypass implemented security restrictions and gain elevated privileges on the target system.