Impact
This vulnerability enables an attacker to gain higher privileges within Microsoft Azure Cognitive Service for Language by exploiting an issue related to Custom Question Answering. An attacker can obtain higher privileges than intended, potentially accessing or manipulating sensitive information or service resources.
Affected Systems
Microsoft Azure Cognitive Service for Language is affected. No specific version details are provided, so all current versions may be vulnerable.
Risk and Exploitability
The CVSS score of 9.9 indicates a high severity flaw. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via the service’s API; this inference is drawn from the description. No public exploit has been reported at this time.
OpenCVE Enrichment