Impact
Improper authentication in Microsoft Azure Key Vault permits an attacker without valid credentials to acquire elevated privileges over the network, thereby enabling unauthorized access to stored keys, secrets, and certificates. The flaw is a classic authentication bypass (CWE‑287), meaning the attacker can assume roles or privileges beyond those intended by the administrator, potentially compromising sensitive data and operations.
Affected Systems
Microsoft Azure Key Vault is affected. No specific version range is listed, so all deployed instances may be vulnerable until a patch is applied or the access model is changed.
Risk and Exploitability
The CVSS score of 10.0 reflects a high‑risk vulnerability with full privileges. The EPSS score is below 1%, indicating a very low current exploitation probability, and the vulnerability is not catalogued in CISA’s KEV. Based on the description, it is inferred that an attacker could send crafted authentication requests to bypass the service’s identity validation, which suggests the attack could be performed remotely over the network if the service is exposed.
OpenCVE Enrichment