Impact
Azure Billing allows an attacker to bypass data authenticity verifications, enabling unauthorized privilege elevation within the billing service. The flaw could let an attacker gain higher access rights over the network, potentially manipulating billing information or accessing other protected resources. The weakness is a verification failure (CWE‑345).
Affected Systems
Microsoft Azure Billing service. No specific version details are provided, so the vulnerability applies to any deployment of the Azure Billing product that lacks the latest security updates.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity, while the EPSS score of less than 1% suggests that exploitation is unlikely at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over a network where the attacker can send forged data to the billing service without proper authentication or validation.
OpenCVE Enrichment