Impact
Improper handling of file paths in Microsoft Application Insights Profiler allows an attacker who already has some authorization to perform a path traversal attack, leading to elevation of privileges over the network. The weakness is a classic path traversal flaw (CWE-22). An attacker can manipulate the profiler’s input paths to access files outside the intended directory and potentially execute code or read restricted configuration. This can materialize as a full privilege takeover of the profiling service and the host environment, compromising confidentiality, integrity, and availability of all monitored applications.
Affected Systems
Microsoft Application Insights Profiler is affected. No specific version information is provided in the advisory, so all installations of this product are at potential risk until a patch is applied.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, with a pronounced impact if exploited. EPSS data is not available and the vulnerability is not listed in CISA KEV. The attack likely occurs over the network by a user with some existing authorization, as the path traversal flaw requires access to the profiler’s management interface. Because the flaw is exposed in a remote service, any authenticated user that can send crafted requests to the tracer can abuse it to escape the intended directory. The absence of EPSS data limits precise estimation of exploitation likelihood, but the high CVSS score and network exposure suggest a significant risk, especially in environments where the profiler is exposed to untrusted networks.
OpenCVE Enrichment