Microsoft Azure Stack Hub Information Disclosure Vulnerability

Vulnerability

A vulnerability in Azure Stack Hub allows an authorized attacker to locally disclose private personal information, such as administrator account passwords, to an unauthorized actor. This issue arises from the exposure of sensitive data in the logs.

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of private personal information, including administrator account passwords, in the logs.

Remediation

Users can apply the official security update available through the Microsoft Update Catalog. Instructions for downloading this update are provided in the Azure Stack Hub Release Notes.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
3.5
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.