Microsoft has patched 32 vulnerabilities in the Azure Site Recoverythat could allow attackers to gain elevated privileges or perform remote code execution.
See also: Microsoft Azure: Now has confidential VMs with ephemeral storage

Azure Site Recovery is a disaster recovery service that will automatically stop workloads on secondary sites when a problem.
As part of the July 2022 Patch Tuesday, Microsoft fixed 84 flaws, with the Azure Site Recovery vulnerability accounting for more than a third of the bugs fixed.
Of the thirty-two vulnerabilities fixed in Azure Site Recovery, two allow remote code execution and thirty vulnerabilities allow elevation of privilege.
In an advisory released today, Microsoft states that SQL injection caused most of the privilege escalation errors.
However, Microsoft also highlighted a vulnerability CVE-2022-33675 discovered by Tenable.
The flaw is called CVE-2022-33675 and has a CVSS v3 severity rating of 7.8. It was discovered by researchers at Tenable, who disclosed it to Microsoft on April 8, 2022.
See also: Microsoft launches security defaults for Azure Active Directory (AD) users
attacks exploit vulnerabilities caused by insecure permission in folders that a operating system and loads DLLs required when an application starts.

To execute the attack, a threat actor can create a custom, malicious DLL using the same name as a regular DLL loaded by the Azure Site Recovery application. This malicious DLL is then stored in a folder that Windows searches for, causing it to be loaded and executed when the application starts.
According to Tenable, the ASR “cxprocessserver” service runs with SYSTEM-level privileges by default and its executable file is located in a directory that is incorrectly configured to allow “write” permissions to any user.
This allows regular users to install malicious DLLs (ktmw32.dll) in the directory. Now, when the 'cxprocessserver' process starts, it will load the malicious DLL and execute any of commands with SYSTEM privileges.
Microsoft also published an advisory to provide an overview of all the issues fixed in ASR this month, mentioning SQL injection and remote code execution in the impact section.
See also: Microsoft: Patches for Azure flaw that allows RCE attacks
To address all security issues, be sure to apply updates . Those who cannot apply the patches could mitigate the risk by manually changing the write permission setting on the affected directory.
