Impact
This vulnerability involves a loop with an unreachable exit condition in Azure Active Directory that can be triggered by an unauthorized attacker, leading to a denial of service by exhausting system resources. The flaw is characterized by improper resource management (CWE-400) and an unreachable exit condition (CWE-835). A successful exploitation would render the Azure AD service unavailable to legitimate users, affecting authentication and authorization processes.
Affected Systems
Microsoft Azure Active Directory (all versions) and Microsoft .NET Framework versions 3.5, 3.5/4.7.2, 3.5/4.8, 3.5/4.8.1, 4.6.2/4.7/4.7.1/4.7.2, 4.8, and 4.8.1 are affected.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability is considered high severity, yet the EPSS score indicates an exploitation probability of less than 1% and it is not listed in the CISA KEV catalog. The likely attack vector is remote over the network, requiring an unauthorized attacker to send specially crafted requests to the Azure AD service, causing the infinite loop and service disruption.
OpenCVE Enrichment