CVE-2024-28917

Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azstackhci.operator:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azure.hybridnetwork:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azurekeyvaultsecretsprovider:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.iotoperations.mq:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.networkfabricserviceextension:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.openservicemesh:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.videoindexer:*:*:*:*:*:*:*:*

History

07 Jan 2025, 19:29

Type Values Removed Values Added
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28917 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28917 - Vendor Advisory
CPE cpe:2.3:a:microsoft:azure_arc_extension_microsoft.videoindexer:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.networkfabricserviceextension:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.iotoperations.mq:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azurekeyvaultsecretsprovider:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.openservicemesh:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azstackhci.operator:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azure.hybridnetwork:*:*:*:*:*:*:*:*
First Time Microsoft azure Arc Extension Microsoft.openservicemesh
Microsoft azure Arc Extension Microsoft.azure.hybridnetwork
Microsoft azure Arc Extension Microsoft.azurekeyvaultsecretsprovider
Microsoft azure Arc Extension Microsoft.iotoperations.mq
Microsoft azure Arc Extension Microsoft.azstackhci.operator
Microsoft
Microsoft azure Arc Extension Microsoft.networkfabricserviceextension
Microsoft azure Arc Extension Microsoft.videoindexer
CWE NVD-CWE-noinfo

21 Nov 2024, 09:07

Type Values Removed Values Added
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28917 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28917 -
Summary
  • (es) Vulnerabilidad de elevación de privilegios en el alcance del clúster de extensión de Kubernetes habilitada para Azure Arc

09 Apr 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-09 17:15

Updated : 2025-01-07 19:29


NVD link : CVE-2024-28917

Mitre link : CVE-2024-28917

CVE.ORG link : CVE-2024-28917


JSON object : View

Products Affected

microsoft

  • azure_arc_extension_microsoft.azure.hybridnetwork
  • azure_arc_extension_microsoft.openservicemesh
  • azure_arc_extension_microsoft.videoindexer
  • azure_arc_extension_microsoft.azstackhci.operator
  • azure_arc_extension_microsoft.azurekeyvaultsecretsprovider
  • azure_arc_extension_microsoft.iotoperations.mq
  • azure_arc_extension_microsoft.networkfabricserviceextension
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo