Impact
The vulnerability is a server‑side request forgery (CWE‑918) within the Data Quality component of Microsoft Purview Data Governance. An unauthenticated attacker can cause the service to make internal network requests that the attacker does not normally have permission to perform, effectively allowing escalation of privileges across the network.
Affected Systems
Affected systems include Microsoft Purview Data Governance. No version numbers are disclosed in this advisory, so all deployments of the product that include the Data Quality feature are considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity, but the EPSS score of less than 1% suggests that exploitation is currently unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to submit a request to the Data Quality service that triggers an internal call, which could be exploited if the service fails to validate target URLs or restricts outbound traffic.
OpenCVE Enrichment