CVE-2022-38007HighCVSS 7.8

Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability

Published
September 13, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker who successfully exploited the vulnerability could replace Microsoft-shipped code with their own code, which would then be run as root in the context of a Guest Configuration daemon. On an Azure VM with the Guest Configuration Linux Extension installed, this would run in the context of the GC Policy Agent daemon. On an Azure Arc-enabled server, it could run in the context of the GC Arc Service or Extension Service daemons.

🎯 Affected products2

  • Azure ARC
  • Azure Guest Configuration

✅ Remediation

KBUpgrade Information (Security Update) — fixed build V1.21 KBWhat's New (Security Update) — fixed build 1.22

🔗 References (4)