CVE-2019-1372

CRITICAL

Azure App Service/Antares on Azure Stack - RCE

Title source: llm
STIX 2.1

Description

An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system thereby escaping the Sandbox.The security update addresses the vulnerability by ensuring that Azure App Service sanitizes user inputs., aka 'Azure App Service Remote Code Execution Vulnerability'.

Scores

CVSS v3 10.0
EPSS 0.1783
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

Status published
Products (1)
microsoft/azure_app_service_on_azure_stack < 1.7
Published Oct 10, 2019
Tracked Since Feb 18, 2026