Impact
This vulnerability arises from improper verification of a cryptographic signature in the Microsoft 365 Admin Center, allowing an unauthorized attacker to gain elevated privileges over a network connection. The flaw is identified as CWE-347. An attacker who can reach the Admin Center may elevate their access rights and potentially alter administrative settings or access sensitive tenant data, posing a serious threat to confidentiality and integrity.
Affected Systems
Microsoft 365 Admin Center of Microsoft. No specific version information is disclosed, so all exposed instances of the Admin Center remain potentially vulnerable.
Risk and Exploitability
The CVSS score is 9.8, indicating a critical risk level. EPSS information is not available, and the vulnerability is not flagged in the CISA KEV catalog. The likely attack vector is a network connection to the Microsoft 365 Admin Center, potentially from an unauthenticated or low-privileged actor. Given the high severity and broad availability, the risk of exploitation remains significant.
OpenCVE Enrichment