Elevation of Privilege Vulnerability in Azure CLI
CVE-2024-43591

8.7HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
8 October 2024

Summary

An elevation of privilege vulnerability exists in Azure Command Line Integration (CLI) that could allow an attacker to execute arbitrary code with elevated privileges. This can occur if the Azure CLI is improperly configured or unpatched. Attackers may potentially exploit this vulnerability to access sensitive data and perform unauthorized actions within an Azure environment. It is critical for users and administrators to apply recommended security updates and follow best practices for securing their Azure CLI installations.

Affected Version(s)

Azure CLI Unknown 2.0.0 < 2.65.0

Azure Service Connector Unknown 0.0.0 < 2.65.0

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.