CVE-2024-21364: Microsoft Azure Site Recovery Elevation of Privilege Vulnerability

Overview

Severity
Critical (CVSS 9.3)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2024-Feb
Released
2024-02-13
EPSS Score
0.29% (percentile: 51.9%)

FAQ

How could an attacker exploit this vulnerability? An attacker with local access to a machine with Azure Site Recovery (ASR) can execute code that allows escalating privileges to IUSR (or Anonymous User Identity) and could discover MySQL root password, which could result in the discovery of other stored encrypted credentials. Why is this CVE rated as Moderate severity? The attacker can only elevate their privileges to Root on the specific system or database which they are targeting. System privileges cannot be gained and information relating to other systems or database can not be obtained after elevating their privileges. According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability? An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.

Affected Products (1)

Azure

  • Azure Site Recovery

Security Updates (1)

Acknowledgments

<a href="https://piffd0s.medium.com/">Chris Hernandez</a> with <a href="https://adversaryacademy.com/">Adversary Academy</a>

Revision History

  • 2024-02-13: Information published.