Microsoft Azure Local Cluster Information Disclosure Vulnerability
Vulnerability
A vulnerability exists in Azure Local Cluster due to insufficiently protected credentials, allowing an authorized attacker to locally disclose sensitive information. This could include device information such as tokens, credentials, resource IDs, SAS tokens, user properties, and other confidential data.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, including tokens and credentials, and allow modifications to this disclosed information. Additionally, there may be potential to cause a service crash, disrupting availability.
Remediation
Users can upgrade to version 2.0.16.0 or later of the Azure Local Cluster Telemetry and Diagnostics ARC Extension to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
