QID 92118

Date Published: 2024-02-19

QID 92118: Microsoft Azure File Sync Elevation of Privilege Vulnerability - February 2024

Azure File Sync enables you to centralize your organization's file shares in Azure Files, while keeping the flexibility, performance, and compatibility of a Windows file server.

Affected : Azure File Sync from v14.0 prior to 16.2
Azure File Sync from v17.0 prior to 17.1

QID Detection Logic (Authenticated):
This QID checks for the file version of FileSyncSvc.exe, if this file version is from v14.0 prior to 16.2 it is considered as vulnerable.

Successful exploit could compromise Confidentiality, Integrity and Availability.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to CVE-2024-21397 for more details pertaining to this vulnerability.

    CVEs related to QID 92118

    Software Advisories
    Advisory ID Software Component Link
    Azure File Sync URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21397