CVE-2019-1372 is a critical remote code execution vulnerability affecting Microsoft Azure App Service on Azure Stack. It arises from a buffer overflow due to insufficient length checking, allowing an unprivileged user function to execute code with NT AUTHORITY\system privileges, effectively escaping the sandbox. With a CVSS score of 10.0, this vulnerability is network-exploitable with low complexity, requiring no user interaction, and leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_app_service_on_azure_stack:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.