Azure CycleCloud Elevation of Privilege Vulnerability
CVE-2024-38092

8.8HIGH

Key Information:

Summary

An elevation of privilege vulnerability exists in Azure CycleCloud, allowing an attacker to manipulate user permissions and access systems in unintended ways. When successfully exploited, this vulnerability can enable an adversary to gain higher access rights than intended, affecting not just the integrity of the affected services but potentially compromising sensitive data and resources. Organizations utilizing Azure CycleCloud should promptly assess their instances and apply any necessary patches or mitigations as outlined in Microsoft's vulnerability advisory.

Affected Version(s)

Azure CycleCloud 7.9.0 Unknown 7.9.0 < 8.6.2

Azure CycleCloud 7.9.1 Unknown 7.9.1 < 8.6.2

Azure CycleCloud 7.9.10 Unknown 7.9.10 < 8.6.2

References

EPSS Score

0% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.