CVE-2024-38092: Azure CycleCloud Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 8.8)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2024-Jul
Released
2024-07-09
EPSS Score
9.81% (percentile: 93.0%)

FAQ

What privileges could be gained by an attacker who successfully exploited the vulnerability? The attacker who successfully exploited the vulnerability could elevate privileges to the Administrator role in the vulnerable Azure CycleCloud instance. According to the CVSS metric, privileges required is Low (PR:L). What does that mean for this vulnerability? To exploit this vulnerability an attacker must have an account with the User role assigned. What actions do customers need to take to protect themselves from this vulnerability? Azure CycleCloud versions 7.9.0 - 7.9.11 were retired on 30 September, 2023 as documented here: CycleCloud 7 Retirement Guide. Customers with existing CycleCloud deployments using versions 7.9.0 - 7.9.11 must migrate their resources to CycleCloud version 8.6.2 to be protected by following the instructions here: Upgrading CycleCloud. Customers with existing CycleCloud deployments using versions 8.0.0 - 8.6.0 should update their resources to CycleCloud version 8.6.2 to be protected by following the instructions here: Upgrading CycleCloud.

Affected Products (26)

Azure

  • Azure CycleCloud 7.9.10
  • Azure CycleCloud 8.2.0
  • Azure CycleCloud 8.0.0
  • Azure CycleCloud 8.6.0
  • Azure CycleCloud 7.9.0
  • Azure CycleCloud 7.9.3
  • Azure CycleCloud 7.9.1
  • Azure CycleCloud 7.9.9
  • Azure CycleCloud 7.9.8
  • Azure CycleCloud 7.9.11
  • Azure CycleCloud 8.0.1
  • Azure CycleCloud 7.9.2
  • Azure CycleCloud 7.9.6
  • Azure CycleCloud 7.9.4
  • Azure CycleCloud 7.9.5
  • Azure CycleCloud 7.9.7
  • Azure CycleCloud 8.0.2
  • Azure CycleCloud 8.1.1
  • Azure CycleCloud 8.2.1
  • Azure CycleCloud 8.1.0
  • Azure CycleCloud 8.2.2
  • Azure CycleCloud 8.3.0
  • Azure CycleCloud 8.4.1
  • Azure CycleCloud 8.4.0
  • Azure CycleCloud 8.4.2
  • Azure CycleCloud 8.5.0

Security Updates (1)

Acknowledgments

<a href="https://www.linkedin.com/in/christianbortone/">Christian Bortone</a> with <a href="https://merckgroup.com/">Merck KGaA</a>

Revision History

  • 2024-07-09: Information published.