Impact
An unauthorized attacker can exploit a missing authentication check on a critical function in Microsoft Azure Kubernetes Service, enabling them to elevate privileges over the network. This flaw is a classic example of CWE-306, where a lack of authentication allows an intruder to perform privileged operations. The immediate consequence is that an attacker who can reach the affected service can gain higher-level access, potentially subverting the entire Kubernetes cluster.
Affected Systems
Microsoft Azure Kubernetes Service is the affected product. No specific version information is provided, so all deployments may be vulnerable until a patch is applied.
Risk and Exploitability
The vulnerability scores a perfect 10 on the CVSS scale, indicating maximum severity. The EPSS score is under 1 %, meaning the likelihood of exploitation in the wild is very low at present. The vulnerability is not yet listed in the CISA KEV catalog, implying no known active exploitation. The attack vector is inferred to be over the network, as the description references an unauthorized attacker elevating privileges across a network connection to the service.
OpenCVE Enrichment