CVE-2022-33677 is an Elevation of Privilege vulnerability affecting Microsoft Azure Site Recovery. With a CVSS score of 7.2 (HIGH), it allows a highly privileged attacker to achieve full compromise (confidentiality, integrity, availability) over the affected system with low attack complexity and no user interaction required. Despite its high severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it was mentioned in a BleepingComputer article regarding Microsoft's July 2022 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0, < 9.49CPE match | cpe:2.3:a:microsoft:azure_site_recovery_vmware_to_azure:*:*:*:*:*:*:*:* | ||
< 9.49.6395.1CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_site_recovery:*:*:*:*:vmware_to_azure:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.