QID 92113

Date Published: 2024-02-14

QID 92113: Azure Connected Machine Agent Elevation of Privilege Vulnerability

The Azure Connected Machine agent enables you to manage your Windows and Linux machines hosted outside of Azure on your corporate network or other cloud providers. Affected versions:
All versions before version 1.38

QID Detection Logic: Authenticated
On Windows, this QID detects vulnerable versions by checking the file version.
On Linux, this QID detects vulnerable versions by checking the Azure Arc-enabled version present in "/usr/share/dotnet/shared/Azure Arc-enabled/" and "/root/shared/Azure Arc-enabled" folders.

Prone to Agent Elevation of Privilege Vulnerability

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to CVE-2024-21329

    CVEs related to QID 92113

    Software Advisories
    Advisory ID Software Component Link
    CVE-2024-21329 URL Logo msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-21329