CVE-2022-24515
published 2022-03-09CVE-2022-24515: Azure Site Recovery Elevation of Privilege Vulnerability
PriorityP340high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.65%
83.9th percentile
Azure Site Recovery Elevation of Privilege Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_site_recovery | < 9.47.6219.1 | 9.47.6219.1 |
| microsoft | azure_site_recovery_vmware_to_azure | >= 9.0 < 9.47 | 9.47 |
| msrc | azure_site_recovery_vmware_to_azure | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure Site Recovery Elevation of Privilege Vulnerability
vendor_msrc·2022-03-08·CVSS 6.5
CVE-2022-24515 [MEDIUM] Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, privileges required is high (PR:H). What privileges does an attacker require to exploit this vulnerability?
Successful exploitation of this vulnerability requires an attacker to compromise admin credentials to one of the VMs associated with the configuration server.
FAQ: What is Azure Site Recovery?
Azure Site Recovery helps ensure business continuity by keeping business apps and workloads running during outages. It is a service but also has a few on-premise components.
Please visit this link for more details: About Azure Site Recovery - Azure Site Recovery
To what scenario does this vulnerability apply?
This vulnerability applies to a VMWare-to-Azure scenario. Please visit this link for more deta
GHSA
GHSA-rc59-5q59-7787: Azure Site Recovery Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-03-10·CVSS 8.1
CVE-2022-24519 [HIGH] CWE-269 GHSA-rc59-5q59-7787: Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24469, CVE-2022-24506, CVE-2022-24515, CVE-2022-24518.
GHSA
GHSA-2mjf-69xr-j2p4: Azure Site Recovery Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-03-10·CVSS 8.1
CVE-2022-24506 [HIGH] CWE-522 GHSA-2mjf-69xr-j2p4: Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24469, CVE-2022-24515, CVE-2022-24518, CVE-2022-24519.
GHSA
GHSA-762c-5c53-5979: Azure Site Recovery Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-03-10·CVSS 8.1
CVE-2022-24518 [HIGH] CWE-269 GHSA-762c-5c53-5979: Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24469, CVE-2022-24506, CVE-2022-24515, CVE-2022-24519.
GHSA
GHSA-x65p-q2x9-3hcj: Azure Site Recovery Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-03-10·CVSS 6.5
CVE-2022-24469 [MEDIUM] CWE-269 GHSA-x65p-q2x9-3hcj: Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24506, CVE-2022-24515, CVE-2022-24518, CVE-2022-24519.
GHSA
GHSA-rmv6-xm23-m4c2: Azure Site Recovery Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-03-10·CVSS 8.1
CVE-2022-24515 [HIGH] CWE-269 GHSA-rmv6-xm23-m4c2: Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24469, CVE-2022-24506, CVE-2022-24518, CVE-2022-24519.
No detection rules found.
No public exploits indexed.
Crowdstrike
March 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] March 2022 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
March 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] March 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2022-03-09
Published