Описание
Azure Monitor Agent Elevation of Privilege Vulnerability
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
FAQ
What privileges could an attacker gain with successful exploitation?
An attacker who successfully exploited the vulnerability could elevate their privileges to 'root' user.
How could an attacker exploit this vulnerability?
An attacker could send specially crafted configuration messages to a locally running Azure Monitor Agent service that does not strictly validate incoming requests. By doing so, the attacker may be able to write files on the affected system, which could then be used to run unauthorized code.
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
7.8 High
CVSS3
Связанные уязвимости
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Уязвимость инструмента сбора данных с виртуальных машин (VM) и физических серверов Azure Monitor Agent, связанная с некорректным внешним управлением именем или путем файла, позволяющая нарушителю повысить свои привилегии
EPSS
7.8 High
CVSS3