CVE-2020-0902: Service Fabric Elevation of Privilege

Overview

Severity
N/A
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Mar
Released
2020-03-10
EPSS Score
16.04% (percentile: 94.8%)

Description

An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions. An unauthenticated remote user could gain rights to the Service Fabric File Store Service if the node is exposed externally via SMB or SCP standard ports and they are using the impacted configuration. The update addresses the vulnerability by making ineffective the resources created by the impacted configuration.

FAQ

Is there anything I need to be aware of before I install Service Fabric 7.0 CU4? Yes. Users are required to be on the latest release (Service Fabric 7.0 CU3) before updating to Service Fabric 7.0 CU4. Please use the following numbers when you need a specific version number. CU4 version number is subject to change if rollout finds a blocking issue. Service Fabric 7.0 CU3: 7.0.466.9590 for Windows, 7.0.465.1 for Linux Service Fabric 7.0 CU4: 7.0.470.9590 for Windows, 7.0.469.1 for Linux

Affected Products (1)

Azure

  • Service Fabric

Security Updates (1)

Acknowledgments

Rohit Gurunath of Microsoft Corporation

Revision History

  • 2020-03-10: Information published.