QID 375798
Date Published: 2021-08-11
QID 375798: Microsoft Azure CycleCloud Elevation of Privilege Vulnerability August 2021
Azure CycleCloud is an enterprise-friendly tool for orchestrating and managing High Performance Computing (HPC) environments on Azure.
CVE-2021-36943:Azure CycleCloud Elevation of Privilege Vulnerability.
CVE-2021-33762:Azure CycleCloud Elevation of Privilege Vulnerability.
Affected Software:
Azure CycleCloud prior to 8.2.0
Azure CycleCloud prior to 7.9.10
QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable version of Azure CycleCloud
Successful exploitation allows an attacker to conduct Vulnerability.
Solution
Customers are advised to refer to CVE-2021-33762 and
CVE-2021-36943 for more details pertaining to this vulnerability
Vendor References
- CVE-2021-33762 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-33762 - CVE-2021-36943 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36943 - KB3142345 -
www.microsoft.com/en-us/download/details.aspx?id=103313
CVEs related to QID 375798
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-33762 |
|
||
| CVE-2021-36943 |
|