Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2024-21329

7.3HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
13 February 2024

Summary

The Azure Connected Machine Agent has a vulnerability that allows an attacker to gain elevated privileges within the affected system. By exploiting this flaw, unauthorized users can execute code with higher privileges, potentially compromising system integrity and security. This opens pathways for malicious activities, seeking to exploit the agent's functionality. Organizations using the Azure Connected Machine Agent should review Microsoft’s advisory for detailed mitigation strategies and ensure that their systems are protected against this vulnerability.

Affected Version(s)

Azure Connected Machine Agent Unknown 1.0.0 < 1.38

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.