Impact
Improper access control in Azure Synapse enables an authorized attacker to elevate privileges across the network. The vulnerability is a CWE‑284 weakness where the service does not properly verify a user’s permissions. As a result, individuals with limited access can gain higher authority within Azure Synapse.
Affected Systems
All deployments of Microsoft Azure Synapse are potentially impacted because no specific version or configuration details are disclosed. The vulnerability applies wherever users have legitimate access to the Azure Synapse service, regardless of deployment size or setup.
Risk and Exploitability
The CVSS score of 4.8 indicates medium severity and the EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is authentication‑based: an attacker who already has a valid Azure Synapse account can exploit the improper access control to elevate privileges. No additional prerequisites are explicitly stated. The impact is limited to resources that the elevated user can access within the Azure Synapse environment.
OpenCVE Enrichment