Impact
A missing authentication check on a critical function in Microsoft Azure Kubernetes Service permits an unauthorized attacker to gain elevated privileges across the network. The vulnerability, classified as CWE‑306, means that an adversary can bypass authentication controls and assume higher‑level permissions, potentially compromising the entire Kubernetes cluster. This could allow the attacker to modify resources, deploy malicious workloads, or exfiltrate sensitive data, thus threatening confidentiality, integrity, and availability of the cloud services.
Affected Systems
Devices running Microsoft Azure Kubernetes Service are susceptible. No specific version numbers are cited in the advisory, so all current releases prior to the vendor’s fix are considered vulnerable. Users should verify that their cluster complies with the latest security updates from Microsoft.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity, while the EPSS score of less than 1 % shows that, as of the last assessment, the probability of exploitation is low. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no widespread public exploitation at this time. Nonetheless, because the flaw allows elevation of privileges across the network, the potential impact warrants prompt remediation. The likely attack vector, based on the description, is an attacker compromising the Kubernetes API through network connectivity or the management plane. Attackers would need network connectivity to the Kubernetes API or management plane, meaning that proper network segmentation can reduce exposure, but the root cause—lack of authentication—calls for an immediate patch.
OpenCVE Enrichment