Tag
#Azure App Service
CVE-2023-21777: Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
**According to the CVSS metrics, the attack vector is local (AV:L) and privilege required is low (PR:L). What does that mean for this vulnerability?** An attacker must have access to the targeted worker role and the ability to deploy a malicious application within the worker. The attack itself is carried out locally on the worker role where a malicious application has been deployed.