Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-29989

Опубликовано: 09 апр. 2024
Источник: msrc
CVSS3: 8.4
EPSS Низкий

Описание

Azure Monitor Agent Elevation of Privilege Vulnerability

FAQ

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.

What actions do customers need to take to protect themselves from this vulnerability?

Customers who have disabled Automatic Extension Upgrades or would like to upgrade an extension immediately must manually update their Azure Monitor Agent to the latest version. For more information on how to perform a manual update, see Manage Azure Monitor Agent.

How could an attacker exploit this vulnerability and what privileges could an attacker gain?

An authenticated attacker with read access permissions can exploit this vulnerability to perform arbitrary file and folder deletion on the host where the Azure Monitor Agent is installed.

According to the CVSS metrics, successful exploitation of this vulnerability could lead to no loss of confidentiality (C:N) but have major impact on integrity (I:H) and on availability (A:H). What does that mean for this vulnerability?

This vulnerability does not allow disclosure of any confidential information, but could allow an attacker to delete data that could include data that results in the service being unavailable.

Обновления

ПродуктСтатьяОбновление
Azure Monitor Agent

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 66%
0.0051
Низкий

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
nvd
почти 2 года назад

Azure Monitor Agent Elevation of Privilege Vulnerability

CVSS3: 8.4
github
почти 2 года назад

Azure Monitor Agent Elevation of Privilege Vulnerability

CVSS3: 8.4
fstec
почти 2 года назад

Уязвимость инструмента сбора данных с виртуальных машин (VM) и физических серверов Azure Monitor Agent, связанная с неверным определением ссылки перед доступом к файлу, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 66%
0.0051
Низкий

8.4 High

CVSS3