Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-21397

Опубликовано: 13 фев. 2024
Источник: msrc
CVSS3: 5.3
EPSS Низкий

Описание

Microsoft Azure File Sync Elevation of Privilege Vulnerability

FAQ

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?

Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment and take additional actions prior to exploitation to prepare the target environment.

What privileges could be gained by an attacker who successfully exploited this vulnerability?

An attacker can create new files in directories they do not normally have access to. Those can only be on directories where Azure File Sync is configured, which could include SYSTEM directories. However, the attacker would not gain privileges to read, modify, or delete files.

According to the CVSS metrics, successful exploitation of this vulnerability would not impact confidentiality (C:N), but would have a major impact on integrity (I:H) and have less impact on availability (A:L). What does that mean for this vulnerability?

An attacker who successfully exploited this vulnerability could affect the integrity because they could create new files in system directories. Confidentiality is not affected by a successful attack, because the attacker cannot modify, delete, or read files. A successful exploitation could have come impact on availability because there could be some interruption to the availability of the file server.

Обновления

ПродуктСтатьяОбновление
Azure File Sync v17.0
Azure File Sync v14.0
Azure File Sync v15.0
Azure File Sync v16.0

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 50%
0.00267
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
почти 2 года назад

Microsoft Azure File Sync Elevation of Privilege Vulnerability

CVSS3: 5.3
github
почти 2 года назад

Microsoft Azure File Sync Elevation of Privilege Vulnerability

CVSS3: 5.3
fstec
почти 2 года назад

Уязвимость службы синхронизации данных Microsoft Azure File Sync, связанная с недостатками разграничения доступа, позволяющая нарушителю обойти существующие ограничения безопасности и повысить свои привилегии

EPSS

Процентиль: 50%
0.00267
Низкий

5.3 Medium

CVSS3