Remote Code Execution Vulnerability in Azure IoT Hub Device Client SDK
CVE-2018-8531
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 10 October 2018
What is CVE-2018-8531?
A remote code execution vulnerability has been identified in the Azure IoT Hub Device Client SDK. This issue arises from improper memory access when using the MQTT protocol, potentially allowing an attacker to execute arbitrary code on affected systems. Azure IoT Edge and the Hub Device Client SDK are at risk, which could lead to unauthorized access and manipulation. Organizations using these Azure services should assess their deployments and apply necessary updates to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Azure IoT Edge Azure IoT Edge
Hub Device Client SDK Azure IoT
References
EPSS Score
19% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved