CVE-2023-38176
CVSS 3.1 Score 7.0 of 10 (high)
Details
Published Aug 8, 2023
Updated: May 29, 2024
CWE ID 22
Summary
CVE-2023-38176 is an elevation of privilege vulnerability affecting Azure Arc-Enabled Servers. An attacker who successfully exploits this vulnerability can gain higher levels of access to the server, potentially leading to unauthorized data access or modification. This issue stems from a misconfiguration in the Azure Arc agent, allowing Remote Procedure Call (RPC) calls from unauthenticated sources. Organizations using Azure Arc-Enabled Servers are advised to apply the available patch as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share