Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2022-38007

Опубликовано: 13 сент. 2022
Источник: msrc
CVSS3: 7.8
EPSS Низкий

Описание

Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability

Меры по смягчению последствий

Azure Guest Configuration and Azure Arc are only affected by this vulnerability if they are running on Linux platforms as follows:

ProductPlatform
Azure Arc-enabled serversLinux
Azure Guest ConfigurationGuest Configuration Linux Extension

FAQ

What privileges could be gained by an attacker who successfully exploited the vulnerability?

An attacker who successfully exploited the vulnerability could replace Microsoft-shipped code with their own code, which would then be run as root in the context of a Guest Configuration daemon. On an Azure VM with the Guest Configuration Linux Extension installed, this would run in the context of the GC Policy Agent daemon. On an Azure Arc-enabled server, it could run in the context of the GC Arc Service or Extension Service daemons.

Обновления

ПродуктСтатьяОбновление
Azure ARC
Azure Guest Configuration

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 72%
0.00723
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
больше 3 лет назад

Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability

CVSS3: 7.8
github
больше 3 лет назад

Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability.

CVSS3: 7.8
fstec
больше 3 лет назад

Уязвимость компонента Azure Guest Configuration службы создания, назначения и управления определениями политик Azure Policy и платформы управления Azure Arc, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 72%
0.00723
Низкий

7.8 High

CVSS3