Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-21364

Опубликовано: 13 фев. 2024
Источник: msrc
CVSS3: 9.3
EPSS Низкий

Описание

Microsoft Azure Site Recovery Elevation of Privilege Vulnerability

FAQ

How could an attacker exploit this vulnerability?

An attacker with local access to a machine with Azure Site Recovery (ASR) can execute code that allows escalating privileges to IUSR (or Anonymous User Identity) and could discover MySQL root password, which could result in the discovery of other stored encrypted credentials.

Why is this CVE rated as Moderate severity?

The attacker can only elevate their privileges to Root on the specific system or database which they are targeting. System privileges cannot be gained and information relating to other systems or database can not be obtained after elevating their privileges.

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.

Обновления

ПродуктСтатьяОбновление
Azure Site Recovery

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 51%
0.00285
Низкий

9.3 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.3
nvd
почти 2 года назад

Microsoft Azure Site Recovery Elevation of Privilege Vulnerability

CVSS3: 9.3
github
почти 2 года назад

Microsoft Azure Site Recovery Elevation of Privilege Vulnerability

CVSS3: 9.3
fstec
почти 2 года назад

Уязвимость средства аварийного восстановления Azure Site Recovery, связанная с недостатками разграничения доступа, позволяющая нарушителю обойти существующие ограничения безопасности и повысить свои привилегии

EPSS

Процентиль: 51%
0.00285
Низкий

9.3 Critical

CVSS3