QID 92048
QID 92048: Azure Arc-Enabled Servers Security Update for August 2023
Azure Arc-enabled servers lets you manage Windows and Linux physical servers and virtual machines hosted outside of Azure, on your corporate network, or other cloud provider.
Affected versions:
Azure Arc-enabled before version 1.33
QID Detection Logic: Authenticated
On Windows, this QID detects vulnerable versions of Azure Arc-enabled by checking the file version.
On Linux, this QID detects vulnerable versions of Microsoft Azure Arc-enabled by checking the Azure Arc-enabled version present in "/usr/share/dotnet/shared/Azure Arc-enabled/" and "/root/shared/Azure Arc-enabled" folders.
Successful exploitation of this vulnerability requires an attacker to exploit two separate vulnerabilities to gain elevated privileges.
Solution
Customers are advised to refer to CVE-2023-38176 for more information on these vulnerabilities and their patches.
Vendor References
- CVE-2023-38176 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-38176
CVEs related to QID 92048
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-38176 |
|