PT-2024-8852 · Microsoft · Azure Stack Hci

Alex Naparu

+3

·

Published

2024-10-11

·

Updated

2025-01-23

·

CVE-2024-49060

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The Azure Stack HCI system is affected by an Elevation of Privilege issue, allowing users to gain higher access privileges without permission. This issue potentially puts the system at risk. Exploit information is available, and details can be found at provided links, such as https://t.co/ICSQfpYjOU and https://t.co/k29BKtEtIl. Unfortunately, specific versions of Azure Stack HCI that are affected are not mentioned. However, it is known that this issue affects Azure Stack HCI systems, and users are advised to check the provided links for more information and patches. #AzureStackHCISecurity #ElevationOfPrivilege #AzureSecurity #HCISecurity #CloudSecurity #MicrosoftAzure #PrivilegeEscalation

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2024-10491
CVE-2024-49060

Affected Products

Azure Stack Hci