Microsoft Azure File Sync
cpe:2.3:a:microsoft:azure_file_sync:*:*:*:*:*:*:*
A vulnerability in Azure File Sync has been identified, allowing an authorized attacker to improperly elevate privileges locally. This issue arises from inadequate access control within the application.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.
Users can apply the security update available in Azure File Sync versions 18.3.0.0, 19.2.0.0, 20.1.0.0, and 21.1.0.0. Instructions for downloading this update are available on the Microsoft Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.