Elevation of Privilege Vulnerability Affects Azure Site Recovery
CVE-2024-21364

9.3CRITICAL

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
13 February 2024

Summary

Microsoft Azure Site Recovery has a vulnerability that could allow an attacker to escalate their privileges within the system. This vulnerability poses significant risks, enabling unauthorized users to gain elevated access to sensitive data and functions, thus potentially compromising the integrity of the service. Individuals and organizations using Azure Site Recovery should remain vigilant and apply necessary security measures to mitigate potential risks associated with this issue.

Affected Version(s)

Azure Site Recovery Unknown 2021 < 9.57

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.