PT-2024-1823 · Microsoft · Azure Connected Machine Agent

R4Nger

+1

·

Published

2024-02-13

·

Updated

2024-05-29

·

CVE-2024-21329

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Azure Connected Machine Agent (affected versions not specified)
Description The issue is related to a symbolic link tracking vulnerability in the Azure Connected Machine Agent. Exploitation of this issue may allow an attacker to elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Weakness Enumeration

Related Identifiers

BDU:2024-01567
CVE-2024-21329

Affected Products

Azure Connected Machine Agent