Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2024-38097

7.1HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
8 October 2024

Summary

The Azure Monitor Agent has been found to possess an elevation of privilege vulnerability that could allow unauthorized access and manipulation of system resources by malicious actors. This vulnerability affects various versions of Azure Monitor Agent, posing a significant risk to organizations relying on Azure for monitoring and managing their cloud resources. Prompt remediation is essential to maintain the integrity and security of impacted systems.

Affected Version(s)

Azure Monitor Unknown 1.0.0 < 1.30.0

References

EPSS Score

0% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.