Impact
Affected Microsoft ACI Confidential Containers store sensitive data in cleartext within the Azure Compute Gallery, allowing an authorized attacker to retrieve that information over a network. This leads to an exposure of confidential data without modification or denial of service, and is classified under CWE-312, a cryptographic or data storage weakness. The vulnerability does not grant arbitrary code execution or privilege escalation, but can reveal secrets that may be leveraged in further attacks.
Affected Systems
Microsoft ACI Confidential Containers are impacted; no specific versions were provided in the CNA data or documentation.
Risk and Exploitability
The CVSS base score of 6.5 places the issue in the medium severity range. An EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based and requires authorized access to the gallery, meaning an adversary would need legitimate credentials or internal access to the Azure environment to exploit this weakness.
OpenCVE Enrichment