Impact
A flaw in Microsoft Entra Provisioning Service (SyncFabric) allows an attacker who already has authorized access to the service to gain higher privileges. The vulnerability stems from improper input handling, resulting in an elevation of privilege that could enable the attacker to access or modify resources beyond their intended scope.
Affected Systems
The affected product is Microsoft Entra Provisioning Service (SyncFabric). Specific version details are not disclosed.
Risk and Exploitability
The CVSS score of 9.9 classifies this vulnerability as critical. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated attacker with network visibility; the attacker can exploit the flaw by sending a crafted request that is mistakenly accepted as privileged, leading to control over the service.
OpenCVE Enrichment