Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
How could an attacker exploit this vulnerability? An attacker could host a specially crafted website and convince a user to visit it. When the user visits the site, it could send requests to a vulnerable service running locally on the affected system, allowing the attacker to run commands with elevated privileges. Authentication is not required, but the attack depends on the user visiting the attacker-controlled website. What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. What version should customers install to address this vulnerability? Version 1.1.3464.439 was the first Azure extension for SQL Server version containing the security fix, but that version is no longer available. Customers should upgrade to version 1.1.3518.465 or later. Extension updates are cumulative, so later versions include the fix.
<a href="https://twitter.com/wunderwuzzi23">Johann Rehberger</a> with https://embracethered.com/