Published Thu, Mar 7th, 2024
Platforms
Tenable Research discovered a privilege escalation flaw that allows a user to escalate privileges to that of the root user within the context of a Spark VM. This escalation was achieved because of a permissions issue with scripts utilized by the intelligent caching service (AKA "Vegas") present in the environment.
Synapse Analytics
None required
No tracked CVEs
Entry Status
Finalized
Disclosure Date
Thu, Jan 25th, 2024
Exploitability Period
September 2023 - January 2024
Known ITW Exploitation
-
Detection Methods
None
Piercing Index Rating
-
Discovered by
Jimi Sebree, Tenable