Cisco Talos reports 16 vulnerabilities in Microsoft Azure Sphere’s sponsored research challenge. Vulnerabilities include privilege escalation bug chain to acquire Azure Sphere Capabilities, the most valuable Linux normal-world permissions in the Azure Sphere context. Customers push signed applications to their devices grouped in an Azure Sphere Cloud Tenant (or sideload if in development mode), and are granted with extremely limited permissions by default. All code running on the device must be signed, either the ASX partition or the root of the OSX partition.”]
Source: https://blog.talosintelligence.com/2020/10/Azure-Sphere-Challenge.html