Описание
Azure Connected Machine Agent Elevation of Privilege Vulnerability
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
FAQ
How could an attacker exploit this vulnerability?
An attacker who already has access to the affected system could interfere with a local service port used by ArcProxy and respond with specially crafted authentication data. By doing this, the attacker can cause the service to access and return files that would normally only be available to a more privileged system account, potentially exposing sensitive information.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Azure Connected Machine Agent |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
7.8 High
CVSS3
Связанные уязвимости
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Уязвимость программного средства управления серверами и виртуальными машинами Azure Connected Machine Agent, связанная с ошибками разграничения доступа, позволяющая нарушителю повысить свои привилегии
EPSS
7.8 High
CVSS3