Impact
An attacker can bypass authentication controls in Azure Resource Manager, allowing them to gain higher levels of permission than intended. This flaw permits the unauthorized escalation of privileges to administer resources and potentially deploy malicious services. The weakness is classified as CWE-287, indicating improper authentication.
Affected Systems
Microsoft Azure Resource Manager. No specific version information is provided by the citation; administrators should verify that their ARM instance is up to date.
Risk and Exploitability
The CVSS score of 10 underscores the high severity of this exploitation. Although an EPSS score is not listed and the vulnerability is not currently in the CISA KEV catalog, the nature of the flaw allows a remote attacker with network access to ARM APIs to potentially elevate privileges without credential validation. The impact scope can reach organization-wide resources if the attacker accesses high-privilege accounts. Immediate action is recommended to mitigate the risk.
OpenCVE Enrichment