QID 379058
Date Published: 2023-11-28
QID 379058: Microsoft Azure CLI Improper Control of Generation of Code Vulnerability
The Azure Command-Line Interface (CLI) is a cross-platform command-line tool to connect to Azure and execute administrative commands on Azure resources. It allows the execution of commands through a terminal using interactive command-line prompts or a script.
In the vulnerable versions, Azure CLI contains a vulnerability for potential code injection.
Affected Versions:
Azure CLI versions prior to v2.53.1
QID Detection Logic:(Authenticated)
The QID checks for Windows registry uninstall path to find out the vulnerable versions of Azure CLI installed.
An attacker could successfully exploit this vulnerability can lead to injection of malicious code.
Solution
Microsoft has released patch to remediate this vulenrability.
Vendor References
- CVE-2022-39327 -
msrc.microsoft.com/update-guide/en-US/advisory/CVE-2022-39327
CVEs related to QID 379058
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-39327 |
|