CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-38108

CVSS 9.3v3.1pub. 2024-08-13upd. 2024-08-16

Azure Stack Hub Spoofing Vulnerability

🤖 AI Analysis
How it works

The vulnerability requires user interaction (UI:R) and operates in a changed context (S:C), which is typical for XSS attacks — malicious script is executed in the context of the victim's browser. The attacker does not need any privileges (PR:N) or complex conditions (AC:L), and the attack vector is network-based (AV:N), meaning the attack can be conducted remotely over the Internet. The spoofing mechanism may allow impersonation of legitimate Azure Stack Hub resources or interfaces.

Impact

An attacker can obtain unauthorized access to sensitive information (C:H) and modify data or the user interface (I:H), which may lead to session hijacking, credential theft, or execution of unauthorized actions on behalf of the victim.

Mitigation & patch

Apply patches available from the vendor according to the references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38108). It is recommended to implement the update published by Microsoft as part of the August 2024 Patch Tuesday as soon as possible.

Who is affected

Microsoft Azure Stack Hub — versions indicated in the vendor's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Microsoft Azure Stack Hub

    APP
    Microsoft
    < 1.2311.1.22
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2021-38647CRITICAL9.8⚠ KEVsame product

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

CVE-2024-38220CRITICAL9.0PL ✓same product

Microsoft Azure Stack Hub — Elevation of Privilege (podatność krytyczna)

CVE-2021-38648HIGH7.8⚠ KEVsame product

Open Management Infrastructure Elevation of Privilege Vulnerability

CVE-2021-38649HIGH7.0⚠ KEVsame product

Open Management Infrastructure Elevation of Privilege Vulnerability

CVE-2021-38645HIGH7.8⚠ KEVsame product

Open Management Infrastructure Elevation of Privilege Vulnerability