Azure
CVE-2019-0816 — Azure SSH Keypairs Security Feature Bypass Vulnerability
Executive Summary
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init. Extraneous Microsoft service public keys can be unexpectedly added to the VM authorized keys file in the limited scenarios described in 4491476. For more information on how to know if you are affected and how to protect yourself, please see 4491476. This update addresses this vulnerability by preventing these keys from being added.
Overview
Moderate
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
EPSS Score
0.01403
probability of exploitation in the next 30 days
0.69028 percentile - updated 2026-06-20
View on FIRST.org
Affected Products
1 affected product
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| UbuntuServer:18.04-LTS | 4491476 (Security Update) |
Moderate | Security Feature Bypass | Yes |
Patches
1 patch
| Article | Type | Restart |
|---|---|---|
4491476 |
Security Update | Yes |
Known Exploits
No known exploits have been linked for this CVE yet. When available, exploit references will be sourced from public repositories and may be unverified, incomplete, or non-functional. Always review code carefully before use in any environment.
Acknowledgments
Microsoft has not published researcher acknowledgments for this CVE, or they are not yet reflected in our data source. Check the MSRC advisory directly for the most current credit information.
References
On This Page