Details have now emerged about a patched vulnerability in Azure Service Fabric Explorer (SFX) that could lead to unauthenticated remote code execution.
The vulnerability was first discovered by Orca Security researchers in October 2022 and patched by Microsoft in October. The vulnerability affected the Service Fabric Explorer (SFX) tool and was named Super FabriXSS because of the remote attackers' ability to execute code remotely.
Also this week, Orca Security researchers announced the discovery of a second vulnerability called "Super FabriXSS".
Microsoft tagged the bug as CVE-2023-2383 and thanked Orca for reporting the bug before anyone was affected.
Lidor Ben Shitrit & Roee Sagi are here to give us a great glimpse into performing security research on Azure services and the process behind the scenes of triaging such vulnerabilities and mitigating the them. pic.twitter.com/IS8G8hewv7
— BlueHat IL (@BlueHatIL) March 30, 2023
To request a quotation for the following: Cyber Security, Digital Transformation, MSSP, Penetration Testing, KVKK, GDPR, ISO 27001 and ISO 27701, please click here.