#VU88367 Improper access control in Microsoft products - CVE-2024-28917
Published: April 10, 2024
Azure Arc Cluster microsoft.videoindexer Extension
Azure Arc Cluster microsoft.openservicemesh Extension
Azure Arc Cluster microsoft.networkfabricserviceextension Extension
Azure Arc Cluster microsoft.iotoperations.mq Extension
Azure Arc Cluster microsoft.azurekeyvaultsecretsprovider Extension
Azure Arc Cluster microsoft.azure.hybridnetwork Extension
Azure Arc Cluster microsoft.azstackhci.operator Extension
Microsoft
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Azure Arc-enabled Kubernetes Extension Cluster-Scope. A remote administrator on the local network can bypass implemented security restrictions and gain access to sensitive information.