Elevation of Privilege Vulnerability in Microsoft Azure Active Directory Connect
CVE-2019-1000

5.3MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
16 May 2019

Summary

An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect, specifically in version 1.3.20.0. This flaw allows attackers who have authenticated access to execute two PowerShell cmdlets with elevated privileges. By leveraging this vulnerability, attackers can execute privileged actions within the Azure AD Connect environment, potentially leading to greater access and control over the organizational resources managed by Azure Active Directory. Organizations using this version should take immediate measures to apply patches and restrict access to mitigate the risk.

Affected Version(s)

Microsoft Azure Active Directory Connect = unspecified

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.