CVE-2022-38007HighCVSS 7.8
Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker who successfully exploited the vulnerability could replace Microsoft-shipped code with their own code, which would then be run as root in the context of a Guest Configuration daemon. On an Azure VM with the Guest Configuration Linux Extension installed, this would run in the context of the GC Policy Agent daemon. On an Azure Arc-enabled server, it could run in the context of the GC Arc Service or Extension Service daemons.
🎯 Affected products2
- Azure ARC
- Azure Guest Configuration
✅ Remediation
KBUpgrade Information (Security Update) — fixed build V1.21 KBWhat's New (Security Update) — fixed build 1.22