Executive brief
A critical vulnerability exists in Azure Stack Edge, a cloud-managed hardware appliance used to process data at the network edge. An unauthorized attacker can remotely exploit this flaw to take full control of the device and execute malicious code. This could lead to the complete compromise of data stored on the device, disruption of local operations, and a potential foothold for further attacks on the corporate network.
Technical details
A remote code execution vulnerability exists in Microsoft Azure Stack Edge due to improper validation of user-supplied input affecting file names or paths (CWE-73). An unauthenticated attacker can exploit this vulnerability over the network by sending specially crafted requests that manipulate file system operations. Successful exploitation allows for arbitrary code execution with high privileges on the underlying system. The vulnerability is characterized by a low attack complexity and requires no user interaction. Microsoft has released security updates to address this issue via the MSRC update guide.
Affected products
- Microsoft Azure Stack Edge
Timeline
- 2026-06-09: disclosed: Initial advisory publication by Microsoft and NVD.