Vulnerability Description
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Azure Arc Extension Microsoft.Azstackhci.Operator | >= 1.0.0, < 5.0.5 |
| Microsoft | Azure Arc Extension Microsoft.Azure.Hybridnetwork | >= 1.0.0, < 1.0.2620-162 |
| Microsoft | Azure Arc Extension Microsoft.Azurekeyvaultsecretsprovider | >= 1.0.0, < 1.5.2 |
| Microsoft | Azure Arc Extension Microsoft.Iotoperations.Mq | < 0.3.0-preview |
| Microsoft | Azure Arc Extension Microsoft.Networkfabricserviceextension | >= 1.0.0, < 5.1.3 |
| Microsoft | Azure Arc Extension Microsoft.Openservicemesh | >= 1.0.0, < 1.2.6 |
| Microsoft | Azure Arc Extension Microsoft.Videoindexer | >= 1.0.0, < 1.1.2 |
Related Weaknesses (CWE)
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28917Vendor Advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28917Vendor Advisory
FAQ
What is CVE-2024-28917?
CVE-2024-28917 is a vulnerability with a CVSS score of 6.2 (MEDIUM). Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
How severe is CVE-2024-28917?
CVE-2024-28917 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-28917?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Azure Arc Extension Microsoft.Azstackhci.Operator, Microsoft Azure Arc Extension Microsoft.Azure.Hybridnetwork, Microsoft Azure Arc Extension Microsoft.Azurekeyvaultsecretsprovider, Microsoft Azure Arc Extension Microsoft.Iotoperations.Mq, Microsoft Azure Arc Extension Microsoft.Networkfabricserviceextension.