CVE-2023-36737
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Oct 10, 2023
Updated: May 29, 2024
CWE ID 59
Summary
CVE-2023-36737 is a newly disclosed vulnerability affecting the Azure Network Watcher VM Agent. This issue grants an attacker elevated privileges, allowing them to execute unauthorized operations on Azure-hosted virtual machines. Successful exploitation may result in data theft, unauthorized modifications, or the creation of new administrative accounts. This vulnerability poses a significant risk to organizations using Azure Network Watcher and emphasizes the importance of applying relevant patches as soon as possible to mitigate potential threats.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Microsoft