CRITICAL 10.0 Microsoft
CVE-2022-37968
Azure Arc-enabled Kubernetes cluster Connect Elevation of Privilege Vulnerability
Microsoft Security Update 2022-Oct: Azure Arc-enabled Kubernetes cluster Connect Elevation of Privilege Vulnerability
Affected Products
- Azure Arc-enabled Kubernetes cluster 1.8.11
- Azure Arc-enabled Kubernetes cluster 1.7.18
- Azure Arc-enabled Kubernetes cluster 1.5.8
- Azure Arc-enabled Kubernetes cluster 1.6.19
- Azure Stack Edge
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37968
- https://nvd.nist.gov/vuln/detail/CVE-2022-37968
This critical severity vulnerability with a CVSS score of 10.0 was published on 2022-10-11 via Microsoft. Affected: Azure Arc-enabled Kubernetes cluster 1.8.11, Azure Arc-enabled Kubernetes cluster 1.7.18, Azure Arc-enabled Kubernetes cluster 1.5.8 and 2 more.
Risk Timeline
CVE Disclosed2022-10-11 · 1422 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37968NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2022-37968Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-32213 | Azure AI Foundry Elevation of Privilege Vulnerability | CRITICAL | 10.0 |
| CVE-2026-33105 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 |
| CVE-2026-33107 | Azure Databricks Elevation of Privilege Vulnerability | CRITICAL | 10.0 |
| CVE-2025-59503 | Azure Compute Resource Provider Elevation of Privilege Vulnerability | CRITICAL | 10.0 |
| CVE-2026-56162 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 |
| CVE-2026-65770 | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability | CRITICAL | 10.0 |
vulnfeed aggregates 9119 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.