Headline
CVE-2022-24469: Azure Site Recovery Elevation of Privilege Vulnerability
What privileges does an attacker require to exploit this vulnerability?
No special privileges are required to exploit this vulnerability. An attacker needs to have network connectivity to the replication appliance.
What can an attacker do with the exposed credentials?
An attacker can call Azure Site Recovery APIs provided by the Configuration Server and in turn get access to configuration data including credentials for the protected systems. Using the APIs, the attacker can also modify/delete configuration data which in turn will impact Site Recovery operation.