Impact
A missing authorization check in the Azure SRE Agent allows an attacker who already has authorized network access to elevate their privileges on the host. This flaw, identified as CWE-862, can lead to remote privilege escalation and potentially permit execution of arbitrary code or operations beyond the attacker’s intended scope.
Affected Systems
Microsoft Azure SRE Agent is affected. No specific version information is provided, so all deployments of the agent that do not include the fix are potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified; however, the flaw requires that the attacker already have some level of network or authorized access. The missing authorization check implies that the attack vector is likely remote over a network connection to the agent. Because no workaround is known, the risk remains high until a patch is applied.
OpenCVE Enrichment