Remote Code Execution Vulnerability Affects Azure CycleCloud
CVE-2024-38195

7.8HIGH

Key Information:

Summary

A remote code execution vulnerability exists in Azure CycleCloud, a Microsoft product designed for cloud computing and workflows. This vulnerability enables an attacker to execute arbitrary code on the system, potentially gaining unauthorized access to sensitive information and control over the affected environments. Proper measures should be taken to update and secure any impacted versions to mitigate the risks associated with this vulnerability.

Affected Version(s)

Azure CycleCloud 8.0.0 Unknown 8.0.0 < 8.6.3

Azure CycleCloud 8.0.1 Unknown 8.0.0 < 8.6.3

Azure CycleCloud 8.0.2 Unknown 8.0.0 < 8.6.3

References

EPSS Score

0% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.