PT-2024-4302 · Microsoft+2 · Authentication Library+3

Eli Arbel

+1

·

Published

2024-06-11

·

Updated

2026-05-21

·

CVE-2024-35255

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Azure Identity Libraries and Microsoft Authentication Library (affected versions not specified)
Description The vulnerability in Azure Identity Libraries and Microsoft Authentication Library is related to synchronization errors when using a shared resource, specifically in the DefaultAzureCredential and ManagedIdentityCredential components. This issue can allow an attacker to elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Race Condition

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16593
ALT-PU-2024-16754
AZL-42637
AZL-42646
AZL-42649
AZL-42655
AZL-42664
AZL-42789
AZL-42799
AZL-43323
BDU:2024-04789
CLEANSTART-2026-DD05788
CLEANSTART-2026-DY37532
CLEANSTART-2026-GG94489
CLEANSTART-2026-HX94762
CLEANSTART-2026-TL66481
CLEANSTART-2026-VH41554
CVE-2024-35255
ECHO-D26C-33FC-9077
GHSA-M5VV-6R4H-3VJ9
GHSA-RVJ4-Q8Q5-8GRF
GO-2024-2918
GO-2024-2941
OESA-2025-2066
OESA-2025-2069
OESA-2025-2070
OPENSUSE-SU-2024:14048-1
OPENSUSE-SU-2024:14362-1
OPENSUSE-SU-2024_3345-1
OPENSUSE-SU-2025_0750-1
SUSE-SU-2024:3345-1
SUSE-SU-2024_3345-1
SUSE-SU-2025:0750-1
SUSE-SU-2025_0750-1

Affected Products

Alt Linux
Azure Identity Libraries
Authentication Library
Suse