ID

VAR-202302-1454


CVE

CVE-2023-21777


TITLE

Azure Stack Hub  Elevated Privileges in

Trust: 0.8

sources: JVNDB: JVNDB-2023-001259

DESCRIPTION

Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability

Trust: 1.71

sources: NVD: CVE-2023-21777 // JVNDB: JVNDB-2023-001259 // VULMON: CVE-2023-21777

IOT TAXONOMY

category:['network device']sub_category:hub

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:microsoftmodel:azure app service on azure stackscope:eqversion: -

Trust: 1.0

vendor:マイクロソフトmodel:azure stack hubscope:eqversion: -

Trust: 0.8

vendor:マイクロソフトmodel:azure stack hubscope:eqversion:azure app service on

Trust: 0.8

sources: JVNDB: JVNDB-2023-001259 // NVD: CVE-2023-21777

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-21777
value: HIGH

Trust: 1.0

secure@microsoft.com: CVE-2023-21777
value: HIGH

Trust: 1.0

OTHER: JVNDB-2023-001259
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202302-1113
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2023-21777
baseSeverity: HIGH
baseScore: 8.7
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: LOW
exploitabilityScore: 2.0
impactScore: 6.0
version: 3.1

Trust: 2.0

OTHER: JVNDB-2023-001259
baseSeverity: HIGH
baseScore: 8.7
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: LOW
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2023-001259 // CNNVD: CNNVD-202302-1113 // NVD: CVE-2023-21777 // NVD: CVE-2023-21777

PROBLEMTYPE DATA

problemtype:CWE-284

Trust: 1.0

problemtype:CWE-269

Trust: 1.0

problemtype:Improper authority management (CWE-269) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2023-001259 // NVD: CVE-2023-21777

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202302-1113

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202302-1113

PATCH

title:Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability Security Update Guideurl:https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21777

Trust: 0.8

title:Microsoft Azure App Service Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=225161

Trust: 0.6

sources: JVNDB: JVNDB-2023-001259 // CNNVD: CNNVD-202302-1113

EXTERNAL IDS

db:NVDid:CVE-2023-21777

Trust: 3.4

db:JVNDBid:JVNDB-2023-001259

Trust: 0.8

db:CNNVDid:CNNVD-202302-1113

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:VULMONid:CVE-2023-21777

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2023-21777 // JVNDB: JVNDB-2023-001259 // CNNVD: CNNVD-202302-1113 // NVD: CVE-2023-21777

REFERENCES

url:https://msrc.microsoft.com/update-guide/vulnerability/cve-2023-21777

Trust: 2.3

url:https://nvd.nist.gov/vuln/detail/cve-2023-21777

Trust: 0.8

url:https://www.ipa.go.jp/security/ciadr/vul/20230215-ms.html

Trust: 0.8

url:https://www.jpcert.or.jp/at/2023/at230004.html

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2023-21777/

Trust: 0.6

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2023-21777 // JVNDB: JVNDB-2023-001259 // CNNVD: CNNVD-202302-1113 // NVD: CVE-2023-21777

CREDITS

Ruslan Sayfiev,Denis Faiustov

Trust: 0.6

sources: CNNVD: CNNVD-202302-1113

SOURCES

db:OTHERid: -
db:VULMONid:CVE-2023-21777
db:JVNDBid:JVNDB-2023-001259
db:CNNVDid:CNNVD-202302-1113
db:NVDid:CVE-2023-21777

LAST UPDATE DATE

2025-01-30T21:54:05.618000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2023-21777date:2023-02-14T00:00:00
db:JVNDBid:JVNDB-2023-001259date:2023-03-01T05:36:00
db:CNNVDid:CNNVD-202302-1113date:2023-02-24T00:00:00
db:NVDid:CVE-2023-21777date:2024-05-29T02:15:16.480

SOURCES RELEASE DATE

db:VULMONid:CVE-2023-21777date:2023-02-14T00:00:00
db:JVNDBid:JVNDB-2023-001259date:2023-03-01T00:00:00
db:CNNVDid:CNNVD-202302-1113date:2023-02-14T00:00:00
db:NVDid:CVE-2023-21777date:2023-02-14T20:15:14.860