CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-38175

CVSS 9.6v3.1pub. 2024-08-20upd. 2025-01-29

An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.

🤖 AI Analysis
How it works

The vulnerability results from improper access control (CWE-284) in the Azure Managed Instance for Apache Cassandra service. An attacker possessing valid authentication credentials to the service can, over the network, perform operations beyond the permissions granted to them. The network attack vector (AV:N) and lack of user interaction requirement (UI:N) as well as low attack complexity (AC:L) make exploitation of the vulnerability relatively simple for an authenticated user.

Impact

An attacker can obtain unauthorized, elevated access level to service resources, leading to breach of data confidentiality and integrity (C:H, I:H). Changed scope (S:C) suggests possible impact on resources beyond the directly attacked instance.

Mitigation & patch

Patches available from the vendor should be applied according to references. Detailed update information is available in the Microsoft Security Advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38175. It is also recommended to apply the principle of least privilege and monitor access to instances.

Who is affected

Microsoft Azure Managed Instance for Apache Cassandra — versions indicated in vendor references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Microsoft Azure Managed Instance For Apache Cassandra

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-65770CRITICAL10.0same product

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance f...

CVE-2026-33109CRITICAL9.9PL ✓same product

Nieprawidłowa kontrola dostępu w Azure Managed Instance for Apache Cassandra umożliwia RCE

CVE-2026-33844CRITICAL9.0PL ✓same product

Nieprawidłowa kontrola dostępu w Azure Managed Instance for Apache Cassandra – RCE

CVE-2026-50522CRITICAL9.8⚠ KEVPL ✓same vendor

RCE przez deserializację niezaufanych danych w Microsoft SharePoint

CVE-2026-55040CRITICAL9.1⚠ KEVPL ✓same vendor

Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)