Impact
The vulnerability is an improper access control flaw that allows an authorized attacker to execute arbitrary code over the Azure API Management network interface. This grants full remote code execution capabilities, enabling the attacker to compromise the service and potentially any downstream systems.
Affected Systems
Microsoft Azure API Management (APIM) is the affected product. No specific version ranges are provided in the advisory, so all published APIM instances are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 8 indicates high severity. However, the EPSS score is below 1%, suggesting exploitation attempts are currently rare. The vulnerability is not listed in CISA KEV, implying no known public exploitation. Attackers need an authorized role within APIM; therefore, internal security controls and role management are critical in limiting the attack surface.
OpenCVE Enrichment