Microsoft Patches ‘Dangerous’ RCE Flaw in Azure Cloud Service

Source
Advertisement


Microsoft has patched what researchers called a “dangerous” flaw in its Azure Service Fabric component of the company’s cloud-hosting infrastructure. If exploited, it would have allowed an unauthenticated, malicious actor to execute code on a container hosted on the platform.

Researchers from Orca Security discovered the cross-site scripting (XSS) flaw — which they dubbed Super FabriXss — in December and reported it to Microsoft, which issued a fix for it in March’s round of Patch Tuesday updates, the researchers said in a blog post published March 30, revealing the technical details of the bug.

Advertisement