Impact
This vulnerability arises from improper restriction of the communication channel to intended endpoints in Azure SQL Managed Instance, enabling an attacker who can reach the instance over the network to elevate privileges. The flaw allows a non‑privileged user to gain higher privileges within the managed instance, potentially compromising database contents and other resources that rely on the instance. The underlying weakness corresponds to CWE‑923, which covers improper restrictions in a communication channel that allow an attacker to perform unauthorized actions.
Affected Systems
The affected product is Microsoft Azure SQL Managed Instance, as identified by the CNA vendor and product name. No specific version information is provided in the CNA data, so any instance of Azure SQL Managed Instance that has not been patched according to the Microsoft Security Response Center guidance is considered vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity of this flaw. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified, but the absence of a patch limits remedial options. This vulnerability is not listed in the CISA KEV catalog. Based on the description, the attacker must be able to communicate with the Azure SQL Managed Instance over the network; thus the likely attack vector is a network-based privilege escalation. No conditions such as local user access or specific software execution are indicated, implying that remote attackers with network access may exploit the flaw if no mitigations are in place.
OpenCVE Enrichment