Impact
The vulnerability is a server‑side request forgery (SSRF) in Microsoft Entra Provisioning Service (SyncFabric). An attacker who has authorized access can make the service send arbitrary HTTP requests to internal network resources, thereby elevating their privileges beyond the permissions of the authenticated account. This flaw is identified as CWE‑918.
Affected Systems
Microsoft Entra Provisioning Service (SyncFabric) is the only product affected. No specific version or patch level is disclosed, so every current deployment might be vulnerable until the issue is resolved.
Risk and Exploitability
The CVSS score of 9.9 marks it as critical; the EPSS score is below 1%, suggesting a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires only an account with service access and allows the service to send arbitrary, which could expose protected resources. This is inferred from the SSRF description, but the CVE does not specify the extent of further compromise or detail how internal resources might be exploited.
OpenCVE Enrichment