Moderate EPSS 0.01403 2019-03 archive

Executive Summary

A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init. Extraneous Microsoft service public keys can be unexpectedly added to the VM authorized keys file in the limited scenarios described in 4491476. For more information on how to know if you are affected and how to protect yourself, please see 4491476. This update addresses this vulnerability by preventing these keys from being added.

Overview

Moderate
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Security Feature Bypass
Released Mar 12 2019
Last Updated Mar 12 2019
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.01403 — 0.69028 percentile

EPSS Score

0.01403
probability of exploitation in the next 30 days
0.69028 percentile - updated 2026-06-20
View on FIRST.org

Affected Products

1 affected product
Product KB Article Severity Impact Restart Required
UbuntuServer:18.04-LTS 4491476 (Security Update) Moderate Security Feature Bypass Yes

Patches

1 patch
Article Type Restart
4491476 Security Update Yes

Known Exploits

Acknowledgments

Microsoft has not published researcher acknowledgments for this CVE, or they are not yet reflected in our data source. Check the MSRC advisory directly for the most current credit information.