Impact
The vulnerability is a missing authorization check in the Azure DNS service that lets an unauthorized user elevate privileges within the network. This flaw maps to CWE-862 and, if exploited, could allow the attacker to gain higher level access to DNS records or management functions, potentially compromising the confidentiality, integrity, and availability of DNS data for the affected Azure subscription.
Affected Systems
Microsoft Azure DNS is affected. Specific affected versions were not disclosed, so any deployment using Azure DNS without the latest updates is potentially at risk.
Risk and Exploitability
The CVSS score of 10.0 signals a critical severity, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in CISA KEV, suggesting that no widespread, publicly known exploitation campaigns have been documented yet. The likely attack vector is over the public network via Azure DNS APIs, where an attacker with no prior authorization can interact with the service and trigger the privilege escalation if the missing check is not addressed.
OpenCVE Enrichment