CVE-2020-35609: Microsoft Azure Sphere

Medium severity, CVSS 5.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially crafted ioctl calls can cause a denial of service. An attacker can write shellcode to trigger this vulnerability.

Affected products

Published 2020-12-22. Last modified 2026-06-17.