Junglewise Threat Intelligence

CVE-2024-35255: GO-2024-2918 - Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity

CVE-2024-35255 · Severity: low · CVSS 3.1 · Published 2024-07-01

Vendors: PyPI, Microsoft, Go.

Executive brief

The Microsoft Authentication Library (MSAL) for .NET is used by applications to authenticate users with Microsoft Entra ID and other identity providers. A vulnerability in MSAL 4.60.3 allows an attacker with local access to exploit the shared token cache mechanism to elevate privileges or access tokens belonging to other users on the same machine, potentially compromising user accounts and application access.

Technical details

This elevation of privilege vulnerability exists in the Microsoft Authentication Library for .NET due to improper access controls on the shared token cache. An attacker with local access to the system can exploit the cache mechanism to access authentication tokens belonging to other users or applications on the same machine. The vulnerability affects MSAL versions up to 4.60.3 and requires local system access to exploit. It does not require authentication or network access. Microsoft has issued patches in later versions of MSAL; however, some platforms (such as UWP) remain limited to vulnerable versions.

Affected products

  • Microsoft Authentication Library for .NET 4.60.3 and earlier
  • Microsoft Azure Identity Libraries affected versions

Timeline

  • 2024-06-11: disclosed

References