← back
CVE-2024-21421

Azure SDK Spoofing Vulnerability

CVSS 7.5 HIGHEPSS 1.8%CWE-1395
In short

Azure SDK contains a spoofing vulnerability that allows attackers to impersonate legitimate services. This flaw could enable unauthorized access to sensitive data or operations by tricking applications into trusting malicious endpoints.

Technical detail

A validation bypass in Azure SDK fails to properly verify service endpoints, allowing an attacker to redirect client connections to attacker-controlled servers. The vulnerability requires network-level access or DNS manipulation; successful exploitation results in client-side credential exposure and unauthorized API calls.

Summary generated and translated by AI from the official description.
Azure SDK Spoofing Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Affected products
Microsoft · Azure SDK

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →