• Latest
  • Trending

Microsoft Releases Patches for Azure Flaw Allowing RCE Attacks

09.05.2022
Ashley Roberts and Dua Lipa enjoy a night out at Chiltern Fire Station

Ashley Roberts and Dua Lipa enjoy a night out at Chiltern Fire Station

04.02.2023
Carolyn Hax: Step-parent not on wedding guest list, per her ex’s orders

Carolyn Hax: Step-parent not on wedding guest list, per her ex’s orders

04.02.2023
Ryan Gallagher and Emily Seebohm lead celebrity arrivals at Twilight Beach Polo in St Kilda

Ryan Gallagher and Emily Seebohm lead celebrity arrivals at Twilight Beach Polo in St Kilda

04.02.2023
Yellowstone 1923 prequel series starring Harrison Ford is renewed for a second season at Paramount+

Yellowstone 1923 prequel series starring Harrison Ford is renewed for a second season at Paramount+

04.02.2023
Hailey Bieber shows off her underwear in a see-through mini dress as she joins hubby Justin for dinner – Daily Mail

Cara Delevingne pulls off a series of very animated facial expressions in a fun clip

04.02.2023
Rebel Wilson hugs baby girl Royce Lillian in cute social media clip

Rebel Wilson hugs baby girl Royce Lillian in cute social media clip

04.02.2023
Manchester City vs Arsenal prediction, odds and betting tips

Wolves vs Liverpool prediction, odds and betting tips

04.02.2023
Kyle Sandilands slams Survivor star George Mladenov for quitting the Australian Labor Party

Kyle Sandilands slams Survivor star George Mladenov for quitting the Australian Labor Party

04.02.2023
Nigella Lawson makes a surprise exit from My Kitchen Rules

Nigella Lawson makes a surprise exit from My Kitchen Rules

04.02.2023
Miss Manners: They ask, I say no.  Suddenly, they are “joking”.

Miss Manners: They ask, I say no. Suddenly, they are “joking”.

04.02.2023
Manchester City vs Arsenal prediction, odds and betting tips

England vs Scotland Six Nations prediction, odds and betting tips

04.02.2023

Urinary Tract Infection Testing Market to Reach $1 Billion Globally by 2031 at a CAGR of 6.2%: Allied Market Research

04.02.2023
Saturday, February 4, 2023
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
No Result
View All Result

Home » Technology » Microsoft Releases Patches for Azure Flaw Allowing RCE Attacks

Microsoft Releases Patches for Azure Flaw Allowing RCE Attacks

09/05/2022 18:46:11
in Technology
0
0
SHARES
Share on WhatsappShare on Facebook

Related posts

Urinary Tract Infection Testing Market to Reach $1 Billion Globally by 2031 at a CAGR of 6.2%: Allied Market Research

04.02.2023

As Winter Bites, Jackery Offers an Affordable Solar Power Solution to Every American

04.02.2023

Microsoft has released security updates to address a security vulnerability affecting Azure Synapse and Azure Data Factory pipelines that could allow attackers to execute commands remotely on the integration execution framework.

The Integration Runtime (IR) compute framework is used by Azure Synapse pipelines and Azure Data Factory to provide data integration functionality in network environments (e.g. data flow, activity dispatch, execution of SQL packages Server Integration Services (SSIS)).

The vulnerability (tracked as CVE-2022-29972 and reported by Orca Security) was mitigated on April 15, with no evidence of exploitation before patches were released.

“The vulnerability was found in the third-party ODBC data connector used to connect to Amazon Redshift, Integration Runtime (IR) in Azure Synapse Pipelines, and Azure Data Factory,” Microsoft explained in a security advisory released today.

“The vulnerability could have allowed an attacker to execute remote commands on an IR infrastructure not limited to a single tenant,” the company added in a Microsoft Security Response Center (MSRC) blog post.

Successful exploitation of this ODBC connector for the Amazon Redshift flaw could allow malicious attackers running tasks in a Synapse pipeline to execute commands remotely.

In the next stage of attack, they could potentially steal the Azure Data Factory service certificate to run commands in another tenant’s Azure Data Factory integration runtimes.

How to mitigate

Microsoft says that customers using the Azure cloud (Azure Integration Runtime) or hosting their own on-premises environment (Self-Hosted Integration Runtime) with automatic updates enabled do not need to take any further steps to mitigate this. fault.

Self-hosted IR customers who have not enabled auto-update have already been notified to protect their deployments via Azure Service Health Alerts (ID: MLC3-LD0).

The company advises them to update their self-hosted IRs to the latest version (5.17.8154.2) available on the Microsoft Download Center.

These updates can be installed on 64-bit systems with .NET Framework 4.7.2 or higher running client and server platforms, including the latest versions (Windows 11 and Windows Server 2022).

“For additional protection, Microsoft recommends configuring Synapse workspaces with a managed virtual network that provides better compute and network isolation,” Redmond added.

“Customers using Azure Data Factory can enable Azure Integration Runtimes with a managed virtual network.”

You can find more information on how to fully mitigate CVE-2022-299 in the “Customer Recommendations and Additional Support” section of the MSRC blog post.

Disclosure schedule:

  • January 4 – Orca reported the issue to Microsoft
  • March 2 – Microsoft has completed initial patch rollout
  • March 11 – Microsoft identifies and notifies customer affected by researcher activity
  • March 30 – Orca notified Microsoft of an additional attack path to the same vulnerability
  • April 13 – Orca notified Microsoft of a second attack path to the same vulnerability
  • April 15 – Additional fixes rolled out for the two newly reported attack paths as well as additional defense-in-depth measures applied

In March, Microsoft said it patched another Azure security vulnerability in December (also reported by Orca Security) that allowed attackers to take full control of other Azure customers’ data by abusing a bug in the Azure Automation service called AutoWarp.

Last month, the company fixed a string of critical bugs in Azure Database for PostgreSQL Flexible Server (known as ExtraReplica) that allowed malicious users to access other customers’ databases after bypassing the ‘authentication.

Other Microsoft Azure vulnerabilities patched by Redmond over the past year include those found in Azure Cosmos DB, the Open Management Infrastructure (OMI) software agent, and Azure App Service.

Related

Previous Post

Orlando man shot dead identified as former NBA player Adreian Payne – WESH 2 Orlando

Next Post

Are Bitcoins Secure? Should You Trade In Bitcoins? Points To Note

Related Posts

Technology

Urinary Tract Infection Testing Market to Reach $1 Billion Globally by 2031 at a CAGR of 6.2%: Allied Market Research

04.02.2023
0

Rising prevalence of urinary tract infections, growing geriatric population, and rapid technological advancements are driving the global urinary tract infection...

Read more

As Winter Bites, Jackery Offers an Affordable Solar Power Solution to Every American

04.02.2023

Qiming Venture Partners Backed Structure Therapeutics Successfully Debuts on Nasdaq

04.02.2023

TWIST BIOSCIENCE SHAREHOLDER ALERT BY FORMER LOUISIANA ATTORNEY GENERAL: KAHN SWICK &; FOTI, LLC REMINDS INVESTORS WITH LOSSES OVER $100,000 of Lead Plaintiff Deadline in Class Action Lawsuit Against Twist Bioscience Corporation – TWST

04.02.2023

GAOTU TECHEDU SHAREHOLDER ALERT BY FORMER LOUISIANA ATTORNEY GENERAL: KAHN SWICK &; FOTI, LLC REMINDS INVESTORS WITH LOSSES GREATER THAN $100,000 of Lead Plaintiff Deadline in Class Action Lawsuit Against Gaotu Techedu Inc. f/k/a GSX Techedu Inc. – GOTU, GSX

04.02.2023

ENOVIX CORPORATION SHAREHOLDER ALERT BY FORMER LOUISIANA ATTORNEY GENERAL: KAHN SWICK &; FOTI, LLC REMINDS INVESTORS WITH LOSSES OVER $100,000 of Lead Plaintiff Deadline in Class Action Lawsuit Against Enovix Corporation – ENVX

04.02.2023
Load More
Next Post

Are Bitcoins Secure? Should You Trade In Bitcoins? Points To Note

Recent Posts

  • Ashley Roberts and Dua Lipa enjoy a night out at Chiltern Fire Station
  • Carolyn Hax: Step-parent not on wedding guest list, per her ex’s orders
  • Ryan Gallagher and Emily Seebohm lead celebrity arrivals at Twilight Beach Polo in St Kilda
  • Yellowstone 1923 prequel series starring Harrison Ford is renewed for a second season at Paramount+
  • Cara Delevingne pulls off a series of very animated facial expressions in a fun clip

Archives

  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • EN

© 2020

No Result
View All Result
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel

© 2020

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.