CVE-2022-33663 is an Elevation of Privilege vulnerability affecting Microsoft Azure Site Recovery (VMware to Azure). With a CVSS score of 6.5 (Medium), this vulnerability allows a highly privileged attacker to achieve high integrity and availability impact without user interaction, though confidentiality is not affected. While there is no known public exploit code or Metasploit/Nuclei modules, the vulnerability has garnered some community discussion and media coverage, indicating awareness. It is not currently listed in CISA's KEV catalog, and its EPSS score suggests a low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0, < 9.49CPE match | cpe:2.3:a:microsoft:azure_site_recovery_vmware_to_azure:*:*:*:*:*:*:*:* | ||
< 9.49.6395.1CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_site_recovery_vmware_to_azure:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.