CVE-2024-30060
published 2024-05-16CVE-2024-30060: Azure Monitor Agent Elevation of Privilege Vulnerability
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.49%
38.9th percentile
Azure Monitor Agent Elevation of Privilege Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_monitor | >= 1.0.0 < 1.26.0 | 1.26.0 |
| microsoft | azure_monitor_agent | < 1.26.0 | 1.26.0 |
| msrc | azure_monitor_agent | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f98h-4x3r-hghq: Azure Monitor Agent Elevation of Privilege Vulnerability
ghsa_unreviewed·2024-05-17
CVE-2024-30060 [HIGH] CWE-59 GHSA-f98h-4x3r-hghq: Azure Monitor Agent Elevation of Privilege Vulnerability
Azure Monitor Agent Elevation of Privilege Vulnerability
Microsoft
Azure Monitor Agent Elevation of Privilege Vulnerability
vendor_msrc·2024-05-14·CVSS 7.8
CVE-2024-30060 [HIGH] CWE-59 Azure Monitor Agent Elevation of Privilege Vulnerability
Azure Monitor Agent Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An authenticated attacker would be able to delete targeted files on a system which could result in them gaining SYSTEM privileges.
FAQ: What actions do customers need to take to protect themselves from this vulnerability?
We released CVE-2024-30060 to help keep customers protected. Customers who have installed the latest updates, or have automatic updates enabled, are already protected. Customers who have disabled Automatic Extension Upgrades or would like to upgrade an extension immediately must manually update their Azure Monitor Agent to the latest version. For more information on how to perform a manual update, see Manage Azure Mo
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-16
Published