Impact
The vulnerability is an improper access control flaw in Azure Resource Manager that allows an authorized attacker to elevate privileges over the network. An authenticated user with insufficient privileges can acquire higher permissions. This flaw is categorized as CWE-284 and the CVSS score of 9.9 reflects a severe risk to confidentiality, integrity, and availability.
Affected Systems
Affected systems are deployments of Microsoft Azure Resource Manager. The CNA data does not list specific versions; therefore any instance of ARM that has not installed the latest security updates may be impacted.
Risk and Exploitability
Risk is high with a CVSS of 9.9, yet the EPSS score is less than 1% indicating a low immediate exploitation probability, and the vulnerability is not in the CISA KEV catalog. The likely attack vector is a network‑based authenticated access to the ARM API, as the flaw requires an authorized account to manipulate role assignments or permissions. If exploited, an attacker could gain broader control over Azure resources.
OpenCVE Enrichment