Impact
The vulnerability allows an authorized attacker to execute arbitrary code by using a specially crafted payload that exploits a flaw in Microsoft Purview. This capability enables the attacker to run code on the Purview service, compromising confidentiality, integrity, and availability of the data stored and processed by the service. The weakness is identified as CWE-35 (XSS) and CWE-94 (Code Injection).
Affected Systems
Microsoft Purview is affected; no specific version information is provided, so all instances of Microsoft Purview that have not applied downstream security updates could be vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates a moderate to high severity risk, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Because the attacker must be an authorized user of Purview, the threat is primarily an internal or privileged actor scenario; no publicly available exploit was reported in the CVE description.
OpenCVE Enrichment