An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions. An unauthenticated remote user could gain rights to the Service Fabric File Store Service if the node is exposed externally via SMB or SCP standard ports and they are using the impacted configuration. The update addresses the vulnerability by making ineffective the resources created by the impacted configuration.
Is there anything I need to be aware of before I install Service Fabric 7.0 CU4? Yes. Users are required to be on the latest release (Service Fabric 7.0 CU3) before updating to Service Fabric 7.0 CU4. Please use the following numbers when you need a specific version number. CU4 version number is subject to change if rollout finds a blocking issue. Service Fabric 7.0 CU3: 7.0.466.9590 for Windows, 7.0.465.1 for Linux Service Fabric 7.0 CU4: 7.0.470.9590 for Windows, 7.0.469.1 for Linux
Rohit Gurunath of Microsoft Corporation