Vulnerability Description
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Azure Health Bot | - |
Related Weaknesses (CWE)
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38109PatchVendor Advisory
FAQ
What is CVE-2024-38109?
CVE-2024-38109 is a vulnerability with a CVSS score of 9.1 (CRITICAL). An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.
How severe is CVE-2024-38109?
CVE-2024-38109 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-38109?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Azure Health Bot.