Improper access control in Azure Connected Machine Agent - CVE-2024-38162

 

Improper access control in Azure Connected Machine Agent - CVE-2024-38162

Published: August 13, 2024


Vulnerability identifier: #VU95860
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38162
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in Azure Connected Machine Agent. A local user can bypass implemented security restrictions and create or delete files in the security context of the NT AUTHORITY SYSTEM account.


Affected software

Azure Connected Machine Agent

How to mitigate CVE-2024-38162

Install updates from vendor's website.


External References

Related Security Bulletins