Impact
Server‑side request forgery in Microsoft Azure AI Search allows a user who already has service access to send arbitrary requests to internal endpoints. This failure of isolation can let the attacker bypass normal network boundaries and elevate their privileges on systems for which they lack direct credentials. The flaw is classified as CWE‑918, meaning the service accepts unsanitized input that is used to construct internal requests. Based on the description, it is inferred that an authenticated session is the prerequisite; only users who can invoke Azure AI Search are able to exploit this SSRF. The potential impact includes gaining unauthorized data access, modifying or terminating internal resources, and compromising the confidentiality and integrity of the organization’s network.
Affected Systems
Microsoft Azure AI Search. All releases that have not yet incorporated the Microsoft fix are affected; no specific package or SDK version is listed in the advisory.
Risk and Exploitability
The CVSS score of 8.5 signals high severity, and the EPSS score of under 1% indicates that exploitation attempts are expected to be rare. The vulnerability is not currently listed in the CISA KEV catalog. Because the exploit requires an authenticated user to submit the malicious request, the attack surface is limited to legitimate service users. If an attacker succeeds, however, they could create a broad range of malicious actions by directing Azure AI Search to internal endpoints, potentially damaging confidentiality, integrity, or availability of internal systems.
OpenCVE Enrichment