CVE-2024-35255: Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
Other sources
Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity
— Red Hat
Microsoft Azure Identity Libraries and Microsoft Authentication Library could allow a local authenticated attacker to gain elevated privileges on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to elevate privileges and read any file on the file system with SYSTEM access permissions.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/Azure/azure-sdk-for-go/sdk/azidentityto a version that resolves this vulnerability.Fixed in 1.6.0-beta.4.0.20240610221955-50774cd97099 - Upgrade
Upgrade
nuget/Microsoft.Identity.Clientto a version that resolves this vulnerability.Fixed in 4.61.3 - Upgrade
Upgrade
nuget/Microsoft.Identity.Clientto a version that resolves this vulnerability.Fixed in 4.60.4 - Upgrade
Upgrade
maven/com.microsoft.azure:msal4jto a version that resolves this vulnerability.Fixed in 1.15.1 - Upgrade
Upgrade
npm/@azure/msal-nodeto a version that resolves this vulnerability.Fixed in 2.9.2 - Upgrade
Upgrade
nuget/Azure.Identityto a version that resolves this vulnerability.Fixed in 1.11.4 - Upgrade
Upgrade
maven/com.azure:azure-identityto a version that resolves this vulnerability.Fixed in 1.12.2 - Upgrade
Upgrade
npm/@azure/identityto a version that resolves this vulnerability.Fixed in 4.2.1 - Upgrade
Upgrade
pip/azure-identityto a version that resolves this vulnerability.Fixed in 1.16.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.9.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.8.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.15.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.16.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.12.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.6.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.2.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.61.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.11.4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35255?
CVE-2024-35255 is classified as an Elevation of Privilege Vulnerability affecting Azure Identity Libraries and Microsoft Authentication Library.
How do I fix CVE-2024-35255?
To mitigate CVE-2024-35255, update the affected Azure Identity Library or Microsoft Authentication Library to the latest patched version.
Which products are affected by CVE-2024-35255?
CVE-2024-35255 affects various products including Azure Identity Library for .NET, MSAL for Python, MSAL for Java, and more across multiple programming languages.
What vulnerabilities are associated with Azure Identity Libraries in CVE-2024-35255?
CVE-2024-35255 is specifically identified as an Elevation of Privilege Vulnerability within the Azure Identity Libraries and Microsoft Authentication Library.
When was CVE-2024-35255 disclosed?
CVE-2024-35255 was disclosed publicly by Microsoft as part of their security vulnerability updates.