← back
CVE-2024-35252

Azure Storage Movement Client Library Denial of Service Vulnerability

CVSS 7.5 HIGHEPSS 2.5%CWE-1104
In short

The Azure Storage Movement Client Library contains a flaw that allows an attacker to cause the application to stop responding (denial of service) by sending specially crafted requests. This can disrupt services that rely on this library to move or manage data in Azure Storage.

Technical detail

A denial of service vulnerability in Azure Storage Movement Client Library (CWE-1104) with CVSS 7.5 allows remote attackers to exhaust system resources or trigger an unhandled exception through malformed input or requests, causing service unavailability. The vulnerability requires network connectivity to an affected application but no authentication, making it accessible to unauthenticated threat actors.

Summary generated and translated by AI from the official description.
Azure Storage Movement Client Library Denial of Service Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →