ZeroHour

CVE-2020-35608

PoC ×2
CVSS 3.1
7.8 high
EPSS
4%p90
Published
()
Modified
Description

A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an executable memory mapping with controllable content. An attacker can execute a shellcode that uses the PACKET_MMAP functionality to trigger this vulnerability.

Vendors
microsoft
Products
azure sphere
Weakness
CWE-74
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news