Impact
The vulnerability is a server-side request forgery in Azure OpenAI, classified as CWE‑918. It permits an authenticated user to instruct the service to make requests to internal network endpoints, effectively elevating the attacker’s privileges and potentially bypassing normal access controls. This can lead to unauthorized access to protected resources and compromise the confidentiality, integrity, or availability of internal systems.
Affected Systems
All Microsoft Azure OpenAI services are affected. No specific version information is available; every deployment that has not been updated with the latest security patch is considered vulnerable until the patch is applied.
Risk and Exploitability
The CVSS base score of 9.9 indicates a critical severity. The EPSS score of less than 1% suggests a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits. Based on the description, it is inferred that the SSRF can only be triggered by users who already have legitimate access to Azure OpenAI, meaning the attack surface requires authenticated users but can still be leveraged to pivot to other internal services. The critical score combined with a limited attack surface underscores the need for urgent remediation.
OpenCVE Enrichment