Security
Headlines
HeadlinesLatestCVEs

Tag

#Azure

CVE-2022-38017: StorSimple 8000 Series Elevation of Privilege Vulnerability

**Where can I find more information about StorSimple 8000 Series?** StorSimple 8000 series is a hybrid cloud storage solution. Please see StorSimple 8000 series for more information.

Microsoft Security Response Center
#vulnerability#web#Azure#Security Vulnerability
CVE-2021-42306: Azure Active Directory Information Disclosure Vulnerability

**Where can I find more information?** Please see the MSRC Blog here. **What Microsoft services are known to be affected by this vulnerability?** Product/Service Microsoft's Mitigation Customer impact assessment and remediation Azure Automation uses the Application and Service Principal keyCredential APIs when Automation Run-As Accounts are created. Azure Automation deployed an update to the service to prevent private keys data in clear text from being uploaded to Azure AD applications. Run-As accounts created or renewed after 10/15/2021 are not impacted and do not require further action. Automation Run As accounts created with an Azure Automation self-signed certificate between 10/15/2020 and 10/15/2021 that have not been renewed are impacted. Separately customers who bring their own certificates could be affected. This is regardless of the renewal date of the certificate. To identify and remediate impacted Azure AD applications associated with impacted Automation Run-As accou...

CVE-2021-41373: FSLogix Information Disclosure Vulnerability

*What data can be disclosed by this vulnerability?* This vulnerability allows disclosing user data redirected to the profile or Office container via FSLogix Cloud cache. This data can include user profile settings and files.