#VU51350 Information disclosure in Microsoft Server applications


Published: 2021-03-09

Vulnerability identifier: #VU51350

Vulnerability risk: Low

CVSSv3.1: 5.9 [CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-27075

CWE-ID: CWE-200

Exploitation vector: Local network

Exploit availability: No

Vulnerable software:
Microsoft Azure Kubernetes Service
Other software / Other software solutions
Azure Container Instance
Other software / Other software solutions
Azure Spring Cloud
Server applications / Other server solutions
Azure Service Fabric
Server applications / Other server solutions

Vendor: Microsoft

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in Azure Virtual Machine. A remote authenticated attacker on the local network can gain unauthorized access to sensitive information on the system.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Microsoft Azure Kubernetes Service: All versions

Azure Container Instance: All versions

Azure Spring Cloud: All versions

Azure Service Fabric: All versions


External links
http://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27075


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability