CVE-2022-24469
published 2022-03-09CVE-2022-24469: Azure Site Recovery Elevation of Privilege Vulnerability
PriorityP351high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.70%
84.2th percentile
Azure Site Recovery Elevation of Privilege Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_site_recovery | < 9.47.6219.1 | 9.47.6219.1 |
| microsoft | azure_site_recovery_vmware_to_azure | >= 9.0 < 9.47 | 9.47 |
| msrc | azure_site_recovery_vmware_to_azure | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_msrc8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rc59-5q59-7787: Azure Site Recovery Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-03-10·CVSS 8.1
CVE-2022-24519 [HIGH] CWE-269 GHSA-rc59-5q59-7787: Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24469, CVE-2022-24506, CVE-2022-24515, CVE-2022-24518.
GHSA
GHSA-2mjf-69xr-j2p4: Azure Site Recovery Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-03-10·CVSS 8.1
CVE-2022-24506 [HIGH] CWE-522 GHSA-2mjf-69xr-j2p4: Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24469, CVE-2022-24515, CVE-2022-24518, CVE-2022-24519.
GHSA
GHSA-762c-5c53-5979: Azure Site Recovery Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-03-10·CVSS 8.1
CVE-2022-24518 [HIGH] CWE-269 GHSA-762c-5c53-5979: Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24469, CVE-2022-24506, CVE-2022-24515, CVE-2022-24519.
GHSA
GHSA-x65p-q2x9-3hcj: Azure Site Recovery Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-03-10·CVSS 6.5
CVE-2022-24469 [MEDIUM] CWE-269 GHSA-x65p-q2x9-3hcj: Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24506, CVE-2022-24515, CVE-2022-24518, CVE-2022-24519.
GHSA
GHSA-rmv6-xm23-m4c2: Azure Site Recovery Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-03-10·CVSS 8.1
CVE-2022-24515 [HIGH] CWE-269 GHSA-rmv6-xm23-m4c2: Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24469, CVE-2022-24506, CVE-2022-24518, CVE-2022-24519.
Microsoft
Azure Site Recovery Elevation of Privilege Vulnerability
vendor_msrc·2022-03-08·CVSS 8.1
CVE-2022-24469 [HIGH] Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
No special privileges are required to exploit this vulnerability. An attacker needs to have network connectivity to the replication appliance.
FAQ: What is Azure Site Recovery?
Azure Site Recovery helps ensure business continuity by keeping business apps and workloads running during outages. It is a service but also has a few on-premise components.
Please visit this link for more details: About Azure Site Recovery - Azure Site Recovery
To what scenario does this vulnerability apply?
This vulnerability applies to a VMWare-to-Azure scenario. Please visit this link for more details: VMware VM disaster recovery architecture
No detection rules found.
No public exploits indexed.
Qualys
March 2022 Patch Tuesday: Microsoft Releases 92 Vulnerabilities With 3 Critical; Adobe Releases 3 Advisories, 6 Vulnerabilities With 5 Critical.
blogs_qualys·2022-03-08·CVSS 8.8
[HIGH] March 2022 Patch Tuesday: Microsoft Releases 92 Vulnerabilities With 3 Critical; Adobe Releases 3 Advisories, 6 Vulnerabilities With 5 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
Notable Microsoft Vulnerabilities Patched
Notable Adobe Vulnerabilities Patched
Discover and Prioritize Patch Tuesday Vulnerabilities in VMDR
Respond by Patching
Monthly Webinar Series: This Month in Vulnerabilities & Patches
Join the webinar: This Month in Vulnerabilities & Patches
About Patch Tuesday
Contributor
## Microsoft Patch Tuesday Summary
Microsoft has fixed 92 vulnerabilities, including 21 Microsoft Edge vulnerabilities, in the March 2022 update, with three classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday release includes fixes for three publicly disclosed zero-day vulnerabilities as well. As of this writing, none of this month’s list of vulnerabilities is known to be acti
Qualys
March 2022 Patch Tuesday: Microsoft Releases 92 Vulnerabilities With 3 Critical; Adobe Releases 3 Advisories, 6 Vulnerabilities With 5 Critical. | Qualys
blogs_qualys·2022-03-08·CVSS 8.8
[HIGH] March 2022 Patch Tuesday: Microsoft Releases 92 Vulnerabilities With 3 Critical; Adobe Releases 3 Advisories, 6 Vulnerabilities With 5 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- Notable Microsoft Vulnerabilities Patched
- Notable Adobe Vulnerabilities Patched
- Discover and Prioritize Patch Tuesday Vulnerabilities in VMDR
- Respond by Patching
- Monthly Webinar Series: This Month in Vulnerabilities & Patches
- Join the webinar: This Month in Vulnerabilities & Patches
- About Patch Tuesday
- Contributor
## Microsoft Patch Tuesday Summary
Microsoft has fixed 92 vulnerabilities, including 21 Microsoft Edge vulnerabilities, in the March 2022 update, with three classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday release includes fixes for three publicly disclosed zero-day vulnerabilities as well. As of this writing, none of this month’s list of vulnerabilities is know
Crowdstrike
March 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] March 2022 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
March 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] March 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2022-03-09
Published