Skip to content

Commit

Permalink
Microsoft Azure Network Watcher VM Vulnerability - 20240710002 (#860)
Browse files Browse the repository at this point in the history
  • Loading branch information
Dinindu-Wick authored Jul 11, 2024
1 parent e048355 commit 96bce68
Showing 1 changed file with 24 additions and 0 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Microsoft Azure Network Watcher VM Vulnerability - 20240710002

## Overview

Microsoft Security Response Center has published an advisory for the Azure Network Watcher VM Extension Elevation of Privilege Vulnerability.

## What is vulnerable?

| Product(s) Affected | Version(s) | CVE | CVSS | Severity |
| ------------------- | ---------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ------------- | ---------------------------------------------------------------- |
| Azure Network Watcher VM Extension for Windows | Affected from 1.4.3320.1, before 1.4.3320.1 | [CVE-2024-35261](https://nvd.nist.gov/vuln/detail/CVE-2024-35261) | 7.8 | **High** |

## Recommendation

The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of *48 hours...* (refer [Patch Management](../guidelines/patch-management.md)):

-
| **Release Date** | **Product** | **Articles** | **Download** | **Build Number** |
| ---------------- |---------------------------------------------- |-------------------------------------------------------------------------------------------------------------------------- |------------------------------------------------------------------------------------------------------------------------------- |------------------ |
| Jul 9, 2024 | Azure Network Watcher VM Extension for Windows | [Release notes](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/network-watcher-update?tabs=windows) | [Security Update(s)](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/network-watcher-update?tabs=windows) | 1.4.3320.1 |

## Additional References

- Microsoft Security Response Center: <https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-35261>

0 comments on commit 96bce68

Please sign in to comment.