CVE-2020-35608
EUVD-2020-2327422.12.2020, 20:15
A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an executable memory mapping with controllable content. An attacker can execute a shellcode that uses the PACKET_MMAP functionality to trigger this vulnerability.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| microsoft | azure_sphere | 20.07 |
𝑥
= Vulnerable software versions