KLA12477
Multiple vulnerabilities in Microsoft Azure

Updated: 03/09/2022
Detect date
?
03/08/2022
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Azure Site Recovery can be exploited remotely to execute arbitrary code.
  2. An elevation of privilege vulnerability in Azure Site Recovery can be exploited remotely to gain privileges.
Affected products

Azure Site Recovery VMWare to Azure

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2022-24517
CVE-2022-24520
CVE-2022-24471
CVE-2022-24518
CVE-2022-24468
CVE-2022-24515
CVE-2022-24506
CVE-2022-24470
CVE-2022-24467
CVE-2022-24519
CVE-2022-24469

Impacts
?
ACE 
[?]

PE 
[?]
Related products
Microsoft Azure
Find out the statistics of the vulnerabilities spreading in your region