CVE-2019-0962Microsoft Azure Automation vulnerability

4 documents4 sources
Severity
4.9MEDIUMNVD
EPSS
4.4%
top 10.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 15
Latest updateMay 24

Description

An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for users with contributor role, aka 'Azure Automation Elevation of Privilege Vulnerability'.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wjcq-f88g-4v62: An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for users with contributor role, aka 'Azure Automation Ele2022-05-24
CVEList
CVE-2019-0962: An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for users with contributor role, aka 'Azure Automation Ele2019-07-15

📋Vendor Advisories

1
Microsoft
Azure Automation Elevation of Privilege Vulnerability2019-07-09
CVE-2019-0962 — Microsoft vulnerability | cvebase