Impact
The vulnerability is a server‑side request forgery in Azure OpenAI, allowing an authenticated user to instruct the service to make requests to internal network endpoints. This capability effectively elevates the attacker’s privileges within the organization, enabling them to bypass normal access controls, access protected resources, and potentially compromise confidentiality or integrity. The flaw is classified as CWE‑918, reflecting a lack of proper validation of URLs used server‑side.
Affected Systems
Microsoft Azure OpenAI services are affected. No specific version information is available; all deployments are considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS base score of 9.9 indicates a critical severity, while the EPSS score of less than 1% suggests a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalogue. Because the SSRF can be triggered by users who already have legitimate access to Azure OpenAI, the attack surface is broadened, allowing the attacker to pivot to other internal services and expand their foothold within the network.
OpenCVE Enrichment