Elevated Privileges Through Improper Authorization in Azure Web Apps
CVE-2024-38194

8.4HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
10 September 2024

What is CVE-2024-38194?

An improper authorization vulnerability exists in Azure Web Apps that allows an authenticated attacker to exploit the system to elevate privileges within the network. This flaw can potentially enable unauthorized access to sensitive resources and functionalities, increasing the risk of data compromise and system integrity issues. Organizations utilizing Azure Web Apps should review their security configurations and apply necessary patches to mitigate this vulnerability.

Affected Version(s)

Azure Web Apps Unknown

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.