Impact
The vulnerability lies in Azure SQL Database’s authentication mechanism, allowing an attacker without valid credentials to be incorrectly authenticated and to elevate privileges over a network connection.
Affected Systems
Microsoft Azure SQL Database is the affected product. No specific version range is listed, so the risk applies to all Azure SQL Database deployments that may lack recent mitigations. This includes the cloud-hosted relational databases managed by Microsoft’s Azure platform.
Risk and Exploitability
The CVSS base score of 10 denotes critical severity. EPSS is not available, but the flaw can be exploited from an unauthenticated network client. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a network-based authentication bypass.
OpenCVE Enrichment