First published: Tue Mar 08 2022(Updated: )
Azure Site Recovery Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Azure Site Recovery | <9.47.6219.1 | |
Microsoft Azure Site Recovery |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24471 is classified as a critical remote code execution vulnerability.
To fix CVE-2022-24471, apply the latest update rollup for Azure Site Recovery as specified in the Microsoft documentation.
CVE-2022-24471 affects Microsoft Azure Site Recovery VMWare to Azure versions up to 9.47.6219.1.
CVE-2022-24471 can be exploited to execute arbitrary code on affected systems without proper user authentication.
Currently, applying the specified updates is the main remediation for CVE-2022-24471, without known workarounds.