CVE-2019-0962
published 2019-07-15CVE-2019-0962: An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for users with contributor role, aka 'Azure Automation Elevation of…
PriorityP426medium4.9CVSS 3.0
AVNACLPRHUINSUCHINAN
EPSS
4.29%
90.1th percentile
An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for users with contributor role, aka 'Azure Automation Elevation of Privilege Vulnerability'.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_automation | — | — |
| msrc | azure_automation | — | — |
CVSS provenance
nvdv3.04.9MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_msrc4.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure Automation Elevation of Privilege Vulnerability
vendor_msrc·2019-07-09·CVSS 4.9
CVE-2019-0962 [MEDIUM] Azure Automation Elevation of Privilege Vulnerability
Azure Automation Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Azure Automation “RunAs account” runbooks for users with contributor role. This vulnerability could potentially allow members of an organization to access Key Vault secrets through a runbook, even if these members would personally not have access to that Key Vault.
To exploit this vulnerability, an attacker must be a member of an organization who can run runbooks, with only global admins/co-admins who can create the “run as” account.
Microsoft is addressing the vulnerability by providing the following scripts for existing RunAsAutomation accounts that modify existing roles by excluding access to KeyVault within Azure Automation account.
https://www.powershellgallery.com/pa
GHSA
GHSA-wjcq-f88g-4v62: An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for users with contributor role, aka 'Azure Automation Ele
ghsa_unreviewed·2022-05-24
CVE-2019-0962 [MEDIUM] GHSA-wjcq-f88g-4v62: An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for users with contributor role, aka 'Azure Automation Ele
An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for users with contributor role, aka 'Azure Automation Elevation of Privilege Vulnerability'.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-07-15
Published