Impact
A configuration error in Azure Compute Gallery causes a resource to be initialized with an insecure default, letting an authorized attacker read sensitive data over the network. The flaw results in the accidental exposure of confidential information and is classified as CWE‑1188. No arbitrary code execution or denial of service is possible from the description.
Affected Systems
Microsoft’s Azure Container Instance confidential container service is affected. Microsoft ACI Confidential Containers in Azure Compute Gallery is the product identified. No specific version numbers are disclosed in the available data.
Risk and Exploitability
The vulnerability has a CVSS base score of 6.5, indicating moderate severity, and an EPSS score of less than 1%, implying a very low probability of exploitation. It is not listed in the CISA KEV catalog. Even though the attack requires an authenticated user with authorization to the resource, the low exploitation probability suggests limited risk if proper access controls are in place. Administrators should consider the impact of potential data leakage when evaluating the criticality of the affected container configuration.
OpenCVE Enrichment