An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.
The vulnerability results from improper access control (CWE-284) in the Azure Managed Instance for Apache Cassandra service. An attacker possessing valid authentication credentials to the service can, over the network, perform operations beyond the permissions granted to them. The network attack vector (AV:N) and lack of user interaction requirement (UI:N) as well as low attack complexity (AC:L) make exploitation of the vulnerability relatively simple for an authenticated user.
An attacker can obtain unauthorized, elevated access level to service resources, leading to breach of data confidentiality and integrity (C:H, I:H). Changed scope (S:C) suggests possible impact on resources beyond the directly attacked instance.
Patches available from the vendor should be applied according to references. Detailed update information is available in the Microsoft Security Advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38175. It is also recommended to apply the principle of least privilege and monitor access to instances.
Microsoft Azure Managed Instance for Apache Cassandra — versions indicated in vendor references.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NMicrosoft Azure Managed Instance For Apache Cassandra
APPMicrosoftall versions
Related vulnerabilities
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance f...
Nieprawidłowa kontrola dostępu w Azure Managed Instance for Apache Cassandra umożliwia RCE
Nieprawidłowa kontrola dostępu w Azure Managed Instance for Apache Cassandra – RCE
RCE przez deserializację niezaufanych danych w Microsoft SharePoint
Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)