Azure
CVE-2019-0816 — Azure SSH Keypairs Security Feature Bypass Vulnerability
Executive Summary
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init. Extraneous Microsoft service public keys can be unexpectedly added to the VM authorized keys file in the limited scenarios described in 4491476 . For more information on how to know if you are affected and how to protect yourself, please see 4491476 . This update addresses this vulnerability by preventing these keys from being added.
Overview
5.1
CVSS MEDIUM
Moderate
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
CVSS Vector
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
ATTACK VECTOR
Local
ATTACK COMPLEXITY
High
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
EPSS Score
0.01403
probability of exploitation in the next 30 days
0.69749 percentile - updated 2026-07-25
View on FIRST.org
Affected Products
1 affected product
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| UbuntuServer:18.04-LTS | 4491476 (Security Update) |
Moderate | Security Feature Bypass | Yes |
Patches
1 patch
| Article | Type | Restart |
|---|---|---|
4491476 |
Security Update | Yes |
Known Exploits
No known exploits have been linked for this CVE yet. When available, exploit references will be sourced from public repositories and may be unverified, incomplete, or non-functional. Always review code carefully before use in any environment.
Acknowledgments
None
References
On This Page