SB2024041063 - Remote code execution in Microsoft Azure Migrate 



SB2024041063 - Remote code execution in Microsoft Azure Migrate

Published: April 10, 2024

Security Bulletin ID SB2024041063
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authorization (CVE-ID: CVE-2024-26193)

The vulnerability allows a remote user to bypass authorization.

The vulnerability exists due to improper authorization checks in Azure Migrate. An administrator on the local network can execute arbitrary code on the target system.


Remediation

Install update from vendor's website.