PT-2022-5825 · Microsoft · Azure Guest Configuration+1

Vladimir Abramzon

·

Published

2022-09-13

·

Updated

2025-01-02

·

CVE-2022-38007

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Azure Guest Configuration and Azure Arc-enabled servers (affected versions not specified)
Description The issue is related to insufficient access controls in the Azure Guest Configuration component, which is part of the Azure Policy service and the Azure Arc platform. This can allow an attacker to elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2022-07231
CVE-2022-38007

Affected Products

Azure Arc
Azure Guest Configuration