Impact
The flaw resides in Microsoft Azure Active Directory. An attacker who already has authorized access can modify an identifier that is supposed to be immutable, called "maid". By tampering with this data the attacker can acquire higher privileges than originally granted, as the weakness involves modification of assumed‑immutable data (CWE‑471).
Affected Systems
Microsoft Azure Active Directory is the affected product. The vulnerability applies to any deployment of this identity management service that has not yet been patched for the reported flaw.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. The EPSS score is not available, and the vulnerability is not yet listed in CISA KEV, but that does not reduce the risk. Exploitation requires a valid authenticated session; once an attacker can modify the "maid" value they can elevate privileges across the network. Given the widespread use of Azure AD, the potential impact is substantial and administrators should treat this as a high‑risk issue while monitoring for suspicious activity.
OpenCVE Enrichment