安全研究
安全漏洞
Microsoft Azure Identity Libraries和Authentication Library权限提升漏洞(CVE-2024-35255)
发布日期:2024-06-11
更新日期:2024-06-12
受影响系统:Microsoft Microsoft Azure Identity Libraries for Python
Microsoft Microsoft Azure Identity Libraries for JavaScript
Microsoft Microsoft Azure Identity Libraries for Java
Microsoft Microsoft Azure Identity Libraries for Go
Microsoft Microsoft Azure Identity Libraries for C++
Microsoft Microsoft Azure Identity Libraries for .NET
Microsoft Microsoft Authentication Library (MSAL) for Python
Microsoft Microsoft Authentication Library (MSAL) for Node.js
Microsoft Microsoft Authentication Library (MSAL) for Java
Microsoft Microsoft Authentication Library (MSAL) for .NET
描述:
CVE(CAN) ID:
CVE-2024-35255
Microsoft Authentication Library是一个强大的工具,它允许开发者轻松地集成微软身份平台,包括Azure AD、Microsoft 帐户和Azure AD B2C 身份验证。
Microsoft Azure Identity Libraries和Authentication Library存在权限提升漏洞,攻击者可利用该漏洞提升权限。
<**>
建议:
厂商补丁:
Microsoft
---------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2024-35255浏览次数:250
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载 绿盟科技给您安全的保障 |