Impact
The flaw resides in the cryptographic signature verification routine of Azure Data Factory, permitting an attacker without proper authorization to elevate their privileges across the network. This results in the attacker gaining higher levels of access than intended, potentially compromising the confidentiality, integrity, or availability of data and services governed by the affected instance. The weakness is identified as CWE-347, indicating improper handling of cryptographic signatures.
Affected Systems
Microsoft Azure Data Factory is the affected product; no specific versions are listed.
Risk and Exploitability
The CVSS score of 9.3 reflects a critical severity, and although the EPSS score is not available, the absence of the vulnerability from the CISA KEV catalog suggests that widespread exploitation has not yet been observed. Attacks would likely occur over the network by sending malicious requests that the service mistakenly accepts due to the signature check flaw. No additional prerequisites or environmental conditions are indicated in the description. The potential impact and high score recommend vigilance.
OpenCVE Enrichment