← back
CVE-2024-35252highCWE-1104

Azure Storage Movement Client Library Denial of Service Vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 2.5%
exploitation probability
2.5%top 17% of all CVEs
observed exploitation
nono source reports it
In short

The Azure Storage Movement Client Library contains a flaw that allows an attacker to cause the application to stop responding (denial of service) by sending specially crafted requests. This can disrupt services that rely on this library to move or manage data in Azure Storage.

Technical detail

A denial of service vulnerability in Azure Storage Movement Client Library (CWE-1104) with CVSS 7.5 allows remote attackers to exhaust system resources or trigger an unhandled exception through malformed input or requests, causing service unavailability. The vulnerability requires network connectivity to an affected application but no authentication, making it accessible to unauthenticated threat actors.

Summary generated and translated by AI from the official description.
Azure Storage Movement Client Library Denial of Service Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C