CVE-2024-28917

Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azstackhci.operator:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azure.hybridnetwork:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azurekeyvaultsecretsprovider:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.iotoperations.mq:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.networkfabricserviceextension:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.openservicemesh:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.videoindexer:*:*:*:*:*:*:*:*

History

07 Jan 2025, 19:29

Type Values Removed Values Added
CPE cpe:2.3:a:microsoft:azure_arc_extension_microsoft.networkfabricserviceextension:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azstackhci.operator:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.iotoperations.mq:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azurekeyvaultsecretsprovider:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.videoindexer:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.azure.hybridnetwork:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:azure_arc_extension_microsoft.openservicemesh:*:*:*:*:*:*:*:*
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28917 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28917 - Vendor Advisory
CWE NVD-CWE-noinfo
First Time Microsoft azure Arc Extension Microsoft.azstackhci.operator
Microsoft azure Arc Extension Microsoft.iotoperations.mq
Microsoft azure Arc Extension Microsoft.azurekeyvaultsecretsprovider
Microsoft
Microsoft azure Arc Extension Microsoft.networkfabricserviceextension
Microsoft azure Arc Extension Microsoft.openservicemesh
Microsoft azure Arc Extension Microsoft.azure.hybridnetwork
Microsoft azure Arc Extension Microsoft.videoindexer

21 Nov 2024, 09:07

Type Values Removed Values Added
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28917 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28917 -

09 Apr 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-09 17:15

Updated : 2025-01-07 19:29


NVD link : CVE-2024-28917

Mitre link : CVE-2024-28917

CVE.ORG link : CVE-2024-28917


JSON object : View

Products Affected

microsoft

  • azure_arc_extension_microsoft.azure.hybridnetwork
  • azure_arc_extension_microsoft.openservicemesh
  • azure_arc_extension_microsoft.networkfabricserviceextension
  • azure_arc_extension_microsoft.azurekeyvaultsecretsprovider
  • azure_arc_extension_microsoft.iotoperations.mq
  • azure_arc_extension_microsoft.azstackhci.operator
  • azure_arc_extension_microsoft.videoindexer
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo