CVE-2024-21421
Azure SDK Spoofing Vulnerability
In short
Azure SDK contains a spoofing vulnerability that allows attackers to impersonate legitimate services. This flaw could enable unauthorized access to sensitive data or operations by tricking applications into trusting malicious endpoints.
Technical detail
A validation bypass in Azure SDK fails to properly verify service endpoints, allowing an attacker to redirect client connections to attacker-controlled servers. The vulnerability requires network-level access or DNS manipulation; successful exploitation results in client-side credential exposure and unauthorized API calls.
Summary generated and translated by AI from the official description.
Azure SDK Spoofing Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Affected products
Microsoft · Azure SDKWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →