Security readout for executives and security teams
Plain-English summary
CVE-2022-33675 is a high-severity elevation-of-privilege issue in Microsoft Azure Site Recovery VMware to Azure version 9.0. A user who already has local low-privilege access could potentially gain higher privileges, affecting confidentiality, integrity, and availability.
Executive priority
Treat this as a high-priority infrastructure hardening item where Azure Site Recovery VMware-to-Azure 9.0 is deployed. It requires local access, so urgency depends on who can access those systems and whether vendor remediation is applied.
Technical view
The supplied CVSS v3.1 vector is 7.8 high: local attack vector, low complexity, low privileges required, no user interaction, unchanged scope, and high impact across confidentiality, integrity, and availability. The bundle identifies Azure Site Recovery VMware to Azure 9.0 as affected.
Likely exposure
Exposure is most likely in environments running Microsoft Azure Site Recovery VMware to Azure version 9.0. The source bundle does not identify other affected versions, deployment modes, or compensating controls.
Exploitation context
CISA KEV status is false in the supplied bundle. The CVSS temporal vector includes E:P, indicating proof-of-concept exploitability, but the provided sources do not support claims of active exploitation.
Researcher notes
Evidence is limited to CVE metadata and Microsoft’s advisory reference. The bundle does not provide root-cause details, affected component internals, exploit mechanics, or patch identifiers beyond the vendor advisory direction.
Mitigation direction
- Check the Microsoft MSRC advisory for official remediation guidance.
- Prioritize updates for Azure Site Recovery VMware-to-Azure 9.0 systems.
- Restrict local access to systems hosting affected ASR components.
- Review privileged accounts and local user access on ASR infrastructure.
Validation and detection
- Inventory Azure Site Recovery VMware-to-Azure deployments and versions.
- Confirm whether version 9.0 is present in production or recovery environments.
- Compare installed ASR components against the MSRC advisory status.
- Review local access paths and low-privilege accounts on affected hosts.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Privilege behavior lookup
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2022-33675 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.8 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C1.85.9Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.8HighVector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Source materials
- CVE List V5 sourceCVE List V5
- Azure Site Recovery Elevation of Privilege VulnerabilityCVE reference · vendor-advisory
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
