Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-24469: Azure Site Recovery Elevation of Privilege Vulnerability

What privileges does an attacker require to exploit this vulnerability?

No special privileges are required to exploit this vulnerability. An attacker needs to have network connectivity to the replication appliance.

What can an attacker do with the exposed credentials?

An attacker can call Azure Site Recovery APIs provided by the Configuration Server and in turn get access to configuration data including credentials for the protected systems. Using the APIs, the attacker can also modify/delete configuration data which in turn will impact Site Recovery operation.

Microsoft Security Response Center
#vulnerability#Azure Site Recovery#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2024-49060: Azure Stack HCI Elevation of Privilege Vulnerability