QID 92087
Date Published: 2023-12-13
QID 92087: Azure Connected Machine Agent Security Update for December 2023
The Azure Connected Machine agent enables you to manage your Windows and Linux machines hosted outside of Azure on your corporate network or other cloud providers.
Affected versions:
All versions before version 1.37
QID Detection Logic: Authenticated
On Windows, this QID detects vulnerable versions by checking the file version.
On Linux, this QID detects vulnerable versions by checking the Azure Arc-enabled version present in "/usr/share/dotnet/shared/Azure Arc-enabled/" and "/root/shared/Azure Arc-enabled" folders.
An attacker who successfully exploited the vulnerability could add symlinks and cause an arbitrary file delete as SYSTEM.
Solution
Customers are advised to refer to CVE-2023-35624 for more information on these vulnerabilities and their patches.
Vendor References
- CVE-2023-35624 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-35624
CVEs related to QID 92087
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE 2023 35624 |
|