QID 376710
Date Published: 2022-07-01
QID 376710: Microsoft Service Fabric Elevation of Privilege Vulnerability for June 2022
Azure Service Fabric is Microsoft's platform-as-a-service (PaaS) and a container orchestrator solution used to build and deploy microservices-based cloud applications across a cluster of machines.
An elevation of privilege vulnerability exists in Service Fabric that could be exploited to obtain elevated permissions and seize control of all nodes in a cluster.
Affected Versions:
Service Fabric prior to 9.0.1035.1
QID Detection Logic:
This authenticated Unix QID detects vulnerable FabricHost package versions lesser than 9.0.1035.1
Successful exploitation allows Elevation of privilege.
Solution
Customers are advised to refer to CVE-2022-30137 for updates pertaining to this vulnerability.
Vendor References
- CVE-2022-30137 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-30137
CVEs related to QID 376710
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-30137 |
|