Oct. 25, 2022, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

Azure CLI contained a code injection vulnerability that could be exploited in
a scenario where the host runs a command where parameter values have been provided
by an external untrusted source - these could be specially crafted in such a way
as to exploit the vulnerability, leading to remote code execution on the host.
The vulnerability is only applicable when the Azure CLI command is run on a Windows
machine and with any version of PowerShell and when the parameter …

azure cli code code execution code injection command exploit exploited external host injection parameter remote code remote code execution scenario untrusted vulnerability

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC