CVE-2022-39327 is a critical code injection vulnerability affecting Azure CLI versions prior to 2.40.0 when run on Windows machines with PowerShell, specifically when parameter values contain '&' or '|' symbols. With a CVSS score of 9.8 (CRITICAL), this vulnerability allows for unauthenticated remote code execution with high impact on confidentiality, integrity, and availability. While not listed in CISA KEV, it has garnered significant community discussion and media coverage, though no public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.40.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_command-line_interface:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.