Azure Stack Hub Spoofing Vulnerability
The vulnerability requires user interaction (UI:R) and operates in a changed context (S:C), which is typical for XSS attacks — malicious script is executed in the context of the victim's browser. The attacker does not need any privileges (PR:N) or complex conditions (AC:L), and the attack vector is network-based (AV:N), meaning the attack can be conducted remotely over the Internet. The spoofing mechanism may allow impersonation of legitimate Azure Stack Hub resources or interfaces.
An attacker can obtain unauthorized access to sensitive information (C:H) and modify data or the user interface (I:H), which may lead to session hijacking, credential theft, or execution of unauthorized actions on behalf of the victim.
Apply patches available from the vendor according to the references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38108). It is recommended to implement the update published by Microsoft as part of the August 2024 Patch Tuesday as soon as possible.
Microsoft Azure Stack Hub — versions indicated in the vendor's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NMicrosoft Azure Stack Hub
APPMicrosoft< 1.2311.1.22
Related vulnerabilities
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
Microsoft Azure Stack Hub — Elevation of Privilege (podatność krytyczna)
Open Management Infrastructure Elevation of Privilege Vulnerability
Open Management Infrastructure Elevation of Privilege Vulnerability
Open Management Infrastructure Elevation of Privilege Vulnerability