CVE-2024-28917

Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azstackhci.operator:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azure.hybridnetwork:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azurekeyvaultsecretsprovider:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.iotoperations.mq:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.networkfabricserviceextension:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.openservicemesh:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.videoindexer:*:*:*:*:*:*:*:*

History

07 Jan 2025, 19:29

Type Values Removed Values Added
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28917 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28917 - Vendor Advisory
CWE NVD-CWE-noinfo
First Time Microsoft azure Arc Extension Microsoft.openservicemesh
Microsoft azure Arc Extension Microsoft.videoindexer
Microsoft azure Arc Extension Microsoft.azurekeyvaultsecretsprovider
Microsoft azure Arc Extension Microsoft.azstackhci.operator
Microsoft azure Arc Extension Microsoft.azure.hybridnetwork
Microsoft azure Arc Extension Microsoft.networkfabricserviceextension
Microsoft
Microsoft azure Arc Extension Microsoft.iotoperations.mq
CPE cpe:2.3:a:microsoft:azure_arc_extension_microsoft.videoindexer:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.networkfabricserviceextension:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.openservicemesh:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azstackhci.operator:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.iotoperations.mq:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azure.hybridnetwork:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azurekeyvaultsecretsprovider:*:*:*:*:*:*:*:*

Information

Published : 2024-04-09 17:15

Updated : 2025-01-07 19:29


NVD link : CVE-2024-28917

Mitre link : CVE-2024-28917

CVE.ORG link : CVE-2024-28917


JSON object : View

Products Affected

microsoft

  • azure_arc_extension_microsoft.azure.hybridnetwork
  • azure_arc_extension_microsoft.azurekeyvaultsecretsprovider
  • azure_arc_extension_microsoft.videoindexer
  • azure_arc_extension_microsoft.iotoperations.mq
  • azure_arc_extension_microsoft.azstackhci.operator
  • azure_arc_extension_microsoft.networkfabricserviceextension
  • azure_arc_extension_microsoft.openservicemesh
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo