when will the updated libcurl 7.32.0 < 8.9.1 DoS (CVE-2024-7264) version available in Service Fabric Runtime for Windows

Joshi, S. (Shravan) 0 Reputation points
2024-11-12T14:18:02.3066667+00:00

We have Azure Service Fabric installed on windows Server 2019 as part of SharePoint Workflows.

We recently receive multiple vulnerabilities (CVE-2024-7264) which reports C:\Program Files\Microsoft Service Fabric\bin\Fabric\Fabric.Code\libcurl.dll version to be fixed to version : 8.9.1.

The current Installed version that comes with Service Fabric Runtime for Windows (with latest version 10.1.2493.9590) is : 7.84.0.0.

Could you please let us know in which version of Service Fabric Releases. will this be fixed?

Azure Service Fabric
Azure Service Fabric
An Azure service that is used to develop microservices and orchestrate containers on Windows and Linux.
272 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Sai Krishna Katakam 1,510 Reputation points Microsoft Vendor
    2024-11-13T13:34:11.1666667+00:00

    Hi Joshi, S. (Shravan),

    Thank you for reaching out with your question regarding the libcurl update within Azure Service Fabric. For the most accurate and up-to-date information on when this vulnerability (CVE-2024-7264) will be addressed in an upcoming Service Fabric release, I recommend contacting Microsoft Support directly. They can provide guidance on the update schedule and any potential workarounds.

    Please reach out to Microsoft Support here to get specialized assistance. When submitting your ticket, include any relevant details and screenshots to help expedite troubleshooting.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.