First published: Tue Aug 13 2024(Updated: )
<p>An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.</p>
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Azure Health Bot | ||
Microsoft Azure Health Bot |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-38109 is classified as critical due to its potential for privilege escalation through SSRF.
To fix CVE-2024-38109, update to the latest version of Microsoft Azure Health Bot as provided in official security updates.
CVE-2024-38109 affects users of Microsoft Azure Health Bot who have not implemented the recommended security updates.
CVE-2024-38109 is a Server-Side Request Forgery (SSRF) vulnerability that can be exploited by authenticated attackers.
The potential impacts of CVE-2024-38109 include unauthorized access to network resources and privilege escalation.